ZeroHour

CVE-2023-44221

KEVlarge1

OS Command Injection in SonicWall SMA100 SSL-VPN Management Interface

CISA: SonicWall SMA100 Appliances OS Command Injection Vulnerability

CVSS 3.1
7.2 high
EPSS
76%p100
Published
()
KEV added
AI analysis

SonicWall SMA100 appliances contain an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the SSL-VPN management interface. A remote attacker who is already authenticated with administrative privileges can submit crafted input containing special characters, causing arbitrary operating system commands to be executed on the appliance. Injected commands run as the low-privilege 'nobody' user, which limits immediate access but still yields high-impact confidentiality, integrity, and availability outcomes (CVSS 7.2) and can provide a foothold for further compromise. Affected products are the SMA 200, SMA 210, SMA 400, and SMA 410 appliance firmware and the SMA 500v virtual appliance firmware. The flaw carries a high EPSS score (75.1%, 99th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-01, and reporting indicates both SonicWall and CISA have confirmed active in-the-wild exploitation of this and related SMA100 flaws.

What to do: Upgrade affected SMA100 appliances (SMA 200/210/400/410 and SMA 500v) to the latest vendor-patched firmware per SonicWall's advisory, as required under CISA KEV/BOD 22-01 timelines. Until patched, restrict access to the SSL-VPN management interface to trusted networks and enforce MFA on administrative accounts, since exploitation requires an authenticated administrative session. Given confirmed in-the-wild exploitation, review appliance logs for unauthorized administrative activity or command execution and rotate credentials if compromise is suspected.

Affected
SonicWall SMA 200 firmware
SonicWall SMA 210 firmware
SonicWall SMA 400 firmware
SonicWall SMA 410 firmware
SonicWall SMA 500v firmware
Estimated exposure
large≈tens of thousands of internet-exposed SMA100 SSL-VPN appliances (order 10k–100k) — SMA100 SSL-VPN gateways are typically deployed internet-facing, and public internet-wide scans have historically counted SMA100 appliances in the tens of thousands, making that the best order-of-magnitude estimate for exposed deployments…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

CISA Known Exploited Vulnerability
Affected
SonicWall SMA100 Appliances
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sonicwall
Products
sma 200 firmware, sma 210 firmware, sma 400 firmware, sma 410 firmware, sma 500v firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news