High severity7.2CISA KEVNVD Advisory· Published Dec 5, 2023· Updated Jun 17, 2026
CVE-2023-44221
CVE-2023-44221
Description
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*Range: <=10.2.1.9-57sv
- cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*Range: <=10.2.1.9-57sv
- cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*Range: <=10.2.1.9-57sv
- cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*Range: <=10.2.1.9-57sv
- cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*Range: <=10.2.1.9-57sv
Patches
Vulnerability mechanics
References
2- psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018nvdVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.