CVE-2023-34133: SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SonicWall GMSto a version that resolves this vulnerability.Fixed in 9.3.2-SP1 - Upgrade
Upgrade
SonicWall Analyticsto a version that resolves this vulnerability.Fixed in 2.5.0.4-R7
Event History
Frequently Asked Questions
What is the vulnerability ID for this SonicWall vulnerability?
The vulnerability ID for this SonicWall vulnerability is CVE-2023-34133.
What is the title of the SonicWall vulnerability?
The title of the SonicWall vulnerability is "Improper Neutralization of Special Elements used in an SQL Command ( SQL Injection ) vulnerability in SonicWall GMS and Analytics".
What is the severity of CVE-2023-34133?
The severity of CVE-2023-34133 is high with a value of 7.5.
Which software versions are affected by CVE-2023-34133?
SonicWall GMS versions 9.3.2-SP1 and earlier, and SonicWall Analytics version 2.5.0.4-r7 are affected by CVE-2023-34133.
How can an unauthenticated attacker exploit CVE-2023-34133?
An unauthenticated attacker can exploit CVE-2023-34133 by using SQL injection techniques to extract sensitive information from the application database.