CVE-2023-34128: Critical severity SonicWall Analytics vulnerability
Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue with SonicWall GMS and Analytics?
The vulnerability ID is CVE-2023-34128.
What is the severity level of vulnerability CVE-2023-34128?
The severity level of CVE-2023-34128 is critical.
How does vulnerability CVE-2023-34128 affect SonicWall GMS and Analytics?
Vulnerability CVE-2023-34128 allows unauthorized users to access Tomcat application credentials in SonicWall GMS and Analytics, potentially leading to unauthorized access to the system.
Which versions of SonicWall GMS are affected by vulnerability CVE-2023-34128?
SonicWall GMS versions 9.3.2-SP1 and earlier are affected by vulnerability CVE-2023-34128.
Which versions of SonicWall Analytics are affected by vulnerability CVE-2023-34128?
SonicWall Analytics versions 2.5.0.4-R7 and earlier are affected by vulnerability CVE-2023-34128.
Is there a fix for vulnerability CVE-2023-34128?
Yes, SonicWall has released patches to address vulnerability CVE-2023-34128. It is recommended to update to the latest version of GMS and Analytics.
Where can I find more information about vulnerability CVE-2023-34128?
More information about vulnerability CVE-2023-34128 can be found on the SonicWall PSIRT website and the SonicWall support notices page.