CVE-2023-34127: OS Command Injection
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-34127.
What is the severity of CVE-2023-34127?
The severity of CVE-2023-34127 is high, with a CVSS score of 8.8.
What software is affected by CVE-2023-34127?
CVE-2023-34127 affects SonicWall GMS versions 9.3.2-SP1 and earlier, and SonicWall Analytics version 2.5.0.4-r7.
How can an attacker exploit CVE-2023-34127?
An authenticated attacker can exploit CVE-2023-34127 to execute arbitrary code with root privileges by injecting OS commands.
Is there a fix available for CVE-2023-34127?
Yes, SonicWall has released patches to address the vulnerability. Please refer to the vendor's advisory for more information.