← Back to browse · API

CVE-2023-44221

Severity
HIGH
CVSS
7.2
EPSS
0.74933
Risk score
80.03
CISA KEV
Yes
PoC
No
Published
2025-05-01
Modified
2025-05-01
First seen
2026-08-07
Aliases
EUVD-2023-48580, GHSA-Q6MF-V98H-W783
Products
SonicWall:SMA100 10.2.1.9-57sv and earlier versions, SonicWall:SMA100 Appliances
Sources
euvd EUVD-2023-48580
cisa.gov CVE-2023-44221

Description

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.

References