CVE-2023-34132: Critical severity SonicWall Analytics vulnerability
Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate Pass-the-Hash risk in SonicWall GMS (9.3.2-SP1 and earlier) and Analytics (2.5.0.4-R7 and earlier) by restricting/controlling authentication access paths until the vendor fix is applied (e.g., limit who can authenticate to the affected services).
Event History
Frequently Asked Questions
What is CVE-2023-34132?
CVE-2023-34132 is a vulnerability in SonicWall GMS and Analytics that allows Pass-the-Hash attacks due to the use of password hash instead of password for authentication.
What is the severity of CVE-2023-34132?
CVE-2023-34132 has a severity rating of 9.8 (critical).
Which versions of SonicWall GMS are affected by CVE-2023-34132?
SonicWall GMS version 9.3.2-SP1 and earlier versions are affected by CVE-2023-34132.
Which versions of SonicWall Analytics are affected by CVE-2023-34132?
SonicWall Analytics version 2.5.0.4-R7 and earlier versions are affected by CVE-2023-34132.
How can I fix CVE-2023-34132?
To fix CVE-2023-34132, update your SonicWall GMS to version 9.3.2-SP2 or later, and update your SonicWall Analytics to version 2.5.0.4-R8 or later.