CVE-2023-44221
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
05/12/2023
Last modified:
31/10/2025
Description
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:* | 10.2.1.9-57sv (including) | |
| cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:* | 10.2.1.9-57sv (including) | |
| cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:* | 10.2.1.9-57sv (including) | |
| cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:* | 10.2.1.9-57sv (including) | |
| cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:* | 10.2.1.9-57sv (including) | |
| cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



