Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Oct 2025 08:15:00 +0900


Wed, 22 Oct 2025 05:30:00 +0900


Wed, 22 Oct 2025 04:30:00 +0900


Fri, 02 May 2025 03:15:00 +0900

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-05-01'}


Fri, 02 May 2025 08:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

kev

{'dateAdded': '2025-05-01'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 03 Dec 2024 02:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2025-10-21T23:05:30.150Z

Reserved: 2023-09-26T23:29:39.790Z

Link: CVE-2023-44221

cve-icon Vulnrichment

Updated: 2024-08-02T19:59:51.772Z

cve-icon NVD

Status : Analyzed

Published: 2023-12-05T21:15:07.150

Modified: 2025-10-31T15:56:29.743

Link: CVE-2023-44221

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses