CVE-2023-34130: Critical severity SonicWall Analytics vulnerability
SonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SonicWall GMSto a version that resolves this vulnerability.Fixed in 9.3.2-SP1 and earlier versions - Upgrade
Upgrade
SonicWall Analyticsto a version that resolves this vulnerability.Fixed in 2.5.0.4-R7 and earlier versions
Event History
Frequently Asked Questions
What is CVE-2023-34130?
CVE-2023-34130 is a vulnerability in SonicWall GMS (Global Management System) and Analytics that allows an attacker to decrypt sensitive data due to the use of an outdated encryption algorithm with a hardcoded key.
Which software versions are affected by CVE-2023-34130?
SonicWall GMS versions 9.3.2-SP1 and earlier, as well as SonicWall Analytics versions 2.5.0.4-R7 and earlier, are affected by CVE-2023-34130.
What is the severity of CVE-2023-34130?
CVE-2023-34130 has a severity rating of critical.
How can I fix CVE-2023-34130?
To fix CVE-2023-34130, it is recommended to update SonicWall GMS to version 9.3.2-SP2 or later, and SonicWall Analytics to version 2.5.0.5 or later.
Is there any additional information about CVE-2023-34130?
Yes, you can find additional information about CVE-2023-34130 on the SonicWall PSIRT website (https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010) and the SonicWall support website (https://www.sonicwall.com/support/notices/230710150218060).