CVE-2023-44221Active Exploitation(sonicwall / sma_200)

MEDIUMCVSS 7.2 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for sonicwall sma_200 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-05-22. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sma_200
  • sma_200_firmware
  • sma_210
  • sma_210_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
sma_200sma_200_firmwaresma_210sma_210_firmwaresma_400sma_400_firmwaresma_410sma_410_firmwaresma_500vsma_500v_firmware

1 version affected across 10 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-27: 1PoC Mentioned / Linked · 2026-04-27: 1Active Exploitation · 2026-04-27: 1Technical Details · 2026-04-27: 104-27
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Defused@DefusedCyber
    Active Exploitation

    ⚠️ We are observing heightened activity against SonicWall SMA 100 appliances Multiple IPs have recently hit our honeypot fleet with paired CVE-2024-38475 reads Public PoCs demonstrate the exploit against benign paths, while these operators are reading temp.db and persist.db - session token and credential databases respectively. These two files, when read, could be used to chain into the post-auth command injection (CVE-2023-44221) for full pre-auth RCE. Given these are older vulns, the activity may also be recon ahead of exploitation using a more recent SMA vulnerability. IOCs and details on Defused Radar 👉 http://console.defusedcyber.com/radar

    Post summary

    Observations indicate increased exploitation attempts targeting SonicWall SMA 100 appliances via CVE‑2024‑38475, with attackers reading credential databases and potentially chaining to a pre‑auth RCE (CVE‑2023‑44221). Public PoCs exist, but no patches or mitigations are referenced.

    0612335.8K
    7.4K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
HWsonicwallsma_200---
OSsonicwallsma_200_firmware---
HWsonicwallsma_210---
OSsonicwallsma_210_firmware---
HWsonicwallsma_400---
OSsonicwallsma_400_firmware---
HWsonicwallsma_410---
OSsonicwallsma_410_firmware---
HWsonicwallsma_500v---
OSsonicwallsma_500v_firmware---

Explore more