First published: Thu Jul 13 2023(Updated: )
Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Credit: PSIRT@sonicwall.com PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall Analytics | <=2.5.0.4-r7 | |
SonicWALL Global Management System | <9.3.2 | |
SonicWALL Global Management System | =9.3.2 | |
SonicWALL Global Management System | =9.3.2-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34126 is a vulnerability in SonicWall GMS and Analytics that allows an authenticated attacker to upload files on the underlying filesystem with root privileges.
CVE-2023-34126 affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
The severity of CVE-2023-34126 is high, with a CVSS score of 8.8.
An authenticated attacker can exploit CVE-2023-34126 by uploading files on the underlying filesystem with root privileges.
Yes, SonicWall has released patches to fix this vulnerability. Please refer to the vendor's official website for more information.