CVE-2023-44221
KEVlarge1OS Command Injection in SonicWall SMA100 SSL-VPN Management Interface
CISA: SonicWall SMA100 Appliances OS Command Injection Vulnerability
SonicWall SMA100 appliances contain an OS command injection flaw (CWE-78) caused by improper neutralization of special elements in the SSL-VPN management interface. A remote attacker who is already authenticated with administrative privileges can submit crafted input containing special characters, causing arbitrary operating system commands to be executed on the appliance. Injected commands run as the low-privilege 'nobody' user, which limits immediate access but still yields high-impact confidentiality, integrity, and availability outcomes (CVSS 7.2) and can provide a foothold for further compromise. Affected products are the SMA 200, SMA 210, SMA 400, and SMA 410 appliance firmware and the SMA 500v virtual appliance firmware. The flaw carries a high EPSS score (75.1%, 99th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-01, and reporting indicates both SonicWall and CISA have confirmed active in-the-wild exploitation of this and related SMA100 flaws.
What to do: Upgrade affected SMA100 appliances (SMA 200/210/400/410 and SMA 500v) to the latest vendor-patched firmware per SonicWall's advisory, as required under CISA KEV/BOD 22-01 timelines. Until patched, restrict access to the SSL-VPN management interface to trusted networks and enforce MFA on administrative accounts, since exploitation requires an authenticated administrative session. Given confirmed in-the-wild exploitation, review appliance logs for unauthorized administrative activity or command execution and rotate credentials if compromise is suspected.
| SonicWall SMA 200 firmware | — |
| SonicWall SMA 210 firmware | — |
| SonicWall SMA 400 firmware | — |
| SonicWall SMA 410 firmware | — |
| SonicWall SMA 500v firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
- Affected
- SonicWall SMA100 Appliances
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sonicwall
- Products
- sma 200 firmware, sma 210 firmware, sma 400 firmware, sma 410 firmware, sma 500v firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H