CVE-2023-44221: SonicWall SMA100 Appliances
EPSS76.2%No. 666 of 1739 in KEV
CVE year2023~2 yrs before listing
Same vendor in KEV19
Same product2
| Field | Value |
|---|---|
| Vendor | SonicWall |
| Product | SMA100 Appliances |
| Name | SonicWall SMA100 Appliances OS Command Injection Vulnerability |
| Added to KEV | 2025-05-01 |
| US federal due date | 2025-05-22 |
| Ransomware use | Unknown |
| CWE | CWE-78 |
CISA description
SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2021-20035 | SonicWall SMA100 Appliances | 2025-04-16 | 4.1% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A SonicWall SMA100 Appliances vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-01.