First published: Thu Jul 13 2023(Updated: )
Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Credit: PSIRT@sonicwall.com PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWALL Global Management System | <9.3.2 | |
SonicWALL Global Management System | <9.3.2 | |
SonicWALL Global Management System | =9.3.2 | |
SonicWALL Global Management System | =9.3.2 | |
SonicWALL Global Management System | =9.3.2-sp1 | |
SonicWALL Global Management System | =9.3.2-sp1 | |
SonicWall Analytics | <2.5.0.4 | |
SonicWall Analytics | =2.5.0.4-r7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34123 is a vulnerability related to the use of a hard-coded cryptographic key in SonicWall GMS and SonicWall Analytics.
SonicWall GMS versions 9.3.2-SP1 and earlier are affected by CVE-2023-34123.
SonicWall Analytics versions 2.5.0.4-R7 and earlier are affected by CVE-2023-34123.
CVE-2023-34123 has a severity rating of 7.5 (High).
To fix CVE-2023-34123, it is recommended to update SonicWall GMS to version 9.3.2-SP2 or later, and SonicWall Analytics to version 2.5.0.4-R8 or later.