CVE-2023-44221
HIGHImproper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands…
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
Affected Products
sma 200 firmwaresonicwallsma 210 firmwaresonicwallsma 400 firmwaresonicwallsma 410 firmwaresonicwallsma 500v firmwaresonicwallFrequently Asked Questions
Is CVE-2023-44221 in your stack?
O3 detects CVE-2023-44221 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.