CVE-2023-34129: Path Traversal
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote attacker to traverse the directory and extract arbitrary files using Zip Slip method to any location on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SonicWall GMSto a version that resolves this vulnerability.Fixed in 9.3.2-SP1 - Upgrade
Upgrade
SonicWall Analyticsto a version that resolves this vulnerability.Fixed in 2.5.0.4-R7
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-34129.
What is the severity of CVE-2023-34129?
The severity of CVE-2023-34129 is high, with a severity value of 8.8.
What is the affected software for CVE-2023-34129?
The affected software for CVE-2023-34129 includes SonicWall Global Management System versions up to 9.3.2 and SonicWall Analytics versions up to 2.5.0.4-r7.
How does CVE-2023-34129 work?
CVE-2023-34129 is a 'Path Traversal' vulnerability that allows an authenticated remote attacker to traverse the directory and extract arbitrary files using the Zip Slip method.
Is there a fix available for CVE-2023-34129?
Yes, a fix is available for CVE-2023-34129. Please refer to the referenced links for more information on the fix.