CVE-2023-34126: Malicious File Upload
Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-34126?
CVE-2023-34126 is a vulnerability in SonicWall GMS and Analytics that allows an authenticated attacker to upload files on the underlying filesystem with root privileges.
Which versions of SonicWall GMS and Analytics are affected by CVE-2023-34126?
CVE-2023-34126 affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
What is the severity of CVE-2023-34126?
The severity of CVE-2023-34126 is high, with a CVSS score of 8.8.
How can an attacker exploit CVE-2023-34126?
An authenticated attacker can exploit CVE-2023-34126 by uploading files on the underlying filesystem with root privileges.
Is there a fix available for CVE-2023-34126?
Yes, SonicWall has released patches to fix this vulnerability. Please refer to the vendor's official website for more information.