Lucene search

K
cveSonicwallCVE-2023-44221
HistoryDec 05, 2023 - 9:15 p.m.

CVE-2023-44221

2023-12-0521:15:07
CWE-78
sonicwall
web.nvd.nist.gov
14
cve-2023-44221
security
vulnerability
ssl-vpn
os command injection
sma100

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

32.8%

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a ‘nobody’ user, potentially leading to OS Command Injection Vulnerability.

Affected configurations

Nvd
Node
sonicwallsma_200Match-
AND
sonicwallsma_200_firmwareRange10.2.1.9-57sv
Node
sonicwallsma_210_firmwareRange10.2.1.9-57sv
AND
sonicwallsma_210Match-
Node
sonicwallsma_400_firmwareRange10.2.1.9-57sv
AND
sonicwallsma_400Match-
Node
sonicwallsma_410_firmwareRange10.2.1.9-57sv
AND
sonicwallsma_410Match-
Node
sonicwallsma_500v_firmwareRange10.2.1.9-57sv
AND
sonicwallsma_500vMatch-
VendorProductVersionCPE
sonicwallsma_200-cpe:2.3:h:sonicwall:sma_200:-:*:*:*:*:*:*:*
sonicwallsma_200_firmware*cpe:2.3:o:sonicwall:sma_200_firmware:*:*:*:*:*:*:*:*
sonicwallsma_210_firmware*cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
sonicwallsma_210-cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
sonicwallsma_400_firmware*cpe:2.3:o:sonicwall:sma_400_firmware:*:*:*:*:*:*:*:*
sonicwallsma_400-cpe:2.3:h:sonicwall:sma_400:-:*:*:*:*:*:*:*
sonicwallsma_410_firmware*cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
sonicwallsma_410-cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*
sonicwallsma_500v_firmware*cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
sonicwallsma_500v-cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "platforms": [
      "SMA 200",
      "SMA 210",
      "SMA 400",
      "SMA 410",
      "SMA 500v"
    ],
    "product": "SMA100",
    "vendor": "SonicWall",
    "versions": [
      {
        "status": "affected",
        "version": "10.2.1.9-57sv and earlier versions"
      }
    ]
  }
]

CVSS3

7.2

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

AI Score

7.1

Confidence

High

EPSS

0.001

Percentile

32.8%

Related for CVE-2023-44221