Exploited Vulnerabilities Daily
🌐 English

Home › SonicWall

CVE-2023-44221: SonicWall SMA100 Appliances

EPSS76.2%No. 666 of 1739 in KEV
CVE year2023~2 yrs before listing
Same vendor in KEV19
Same product2
FieldValue
VendorSonicWall
ProductSMA100 Appliances
NameSonicWall SMA100 Appliances OS Command Injection Vulnerability
Added to KEV2025-05-01
US federal due date2025-05-22
Ransomware useUnknown
CWECWE-78

CISA description

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2021-20035SonicWall SMA100 Appliances2025-04-164.1%Unknown

NVD — CVE-2023-44221

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A SonicWall SMA100 Appliances vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-01.