CVE-2023-34123: High severity SonicWall Global Management System vulnerability
Published Jul 12, 2023
·Updated
Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
8 affected components
SonicWall Global Management System<9.3.2
SonicWall Global Management System<9.3.2
SonicWall Global Management System=9.3.2
SonicWall Global Management System=9.3.2
SonicWall Global Management System=9.3.2-sp1
SonicWall Global Management System=9.3.2-sp1
SonicWall Analytics<2.5.0.4
SonicWall Analytics=2.5.0.4-r7
Event History
Jul 12, 2023
CVE Published
via MITRE·11:16 PM
Data Sourced
via MITRE·11:16 PM
DescriptionWeakness
Jul 13, 2023
Data Sourced
12:15 AM
Description
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-34123?
CVE-2023-34123 is a vulnerability related to the use of a hard-coded cryptographic key in SonicWall GMS and SonicWall Analytics.
2
Which versions of SonicWall GMS are affected by CVE-2023-34123?
SonicWall GMS versions 9.3.2-SP1 and earlier are affected by CVE-2023-34123.
3
Which versions of SonicWall Analytics are affected by CVE-2023-34123?
SonicWall Analytics versions 2.5.0.4-R7 and earlier are affected by CVE-2023-34123.
4
What is the severity of CVE-2023-34123?
CVE-2023-34123 has a severity rating of 7.5 (High).
5
How can I fix CVE-2023-34123?
To fix CVE-2023-34123, it is recommended to update SonicWall GMS to version 9.3.2-SP2 or later, and SonicWall Analytics to version 2.5.0.4-R8 or later.