Fixed Intel

CISA Known Exploited Vulnerability

This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.

Remediation Deadline: May 22, 2025

CVE-2023-44221

High
EPSS 21.7%CISA KEV
SonicWall/SMA100 Appliances

Description

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.

EPSS — Exploit Probability

21.7%

Higher than 95.6% of all CVEs

Required Action

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0018 ; https://nvd.nist.gov/vuln/detail/CVE-2023-44221

Risk Assessment

ELEVATED
In CISA KEV

Details

Severity
High
EPSS
21.7%
CISA KEV
Yes
Ransomware
Unknown
Articles
0

Timeline

Published

May 1, 2025

Added to KEV

May 1, 2025

Remediation Due

May 22, 2025

Affected Product

SonicWall

SMA100 Appliances

View all SonicWall CVEs