CVE-2023-34124: Critical severity SonicWall Global Management System vulnerability
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34124?
The severity of CVE-2023-34124 is critical with a severity value of 9.
Which software versions are affected by CVE-2023-34124?
SonicWall GMS versions 9.3.2-SP1 and earlier, and Analytics versions 2.5.0.4-R7 and earlier are affected by CVE-2023-34124.
How does CVE-2023-34124 impact SonicWall GMS and Analytics?
CVE-2023-34124 allows for authentication bypass in SonicWall GMS and Analytics Web Services.
How can I fix CVE-2023-34124?
To fix CVE-2023-34124, update SonicWall GMS to version 9.3.2-SP2 or later, and Analytics to version 2.5.0.5 or later.
Where can I find more information about CVE-2023-34124?
More information about CVE-2023-34124 can be found at the following references: [link 1](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010), [link 2](https://www.sonicwall.com/support/notices/230710150218060), [link 3](http://packetstormsecurity.com/files/174571/Sonicwall-GMS-9.9.9320-Remote-Code-Execution.html).