Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-44221

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.474
EPSS Ranking 97.6%
CVSS Severity
CVSS v3 Score 7.2
Proposed Action
SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.
Ransomware Campaign
Unknown
Products affected by CVE-2023-44221


Contact Us

Shodan ® - All rights reserved