First published: Thu Jul 13 2023(Updated: )
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Credit: PSIRT@sonicwall.com PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall Analytics | <=2.5.0.4-r7 | |
SonicWALL Global Management System | <9.3.2 | |
SonicWALL Global Management System | =9.3.2 | |
SonicWALL Global Management System | =9.3.2-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SonicWall vulnerability is CVE-2023-34133.
The title of the SonicWall vulnerability is "Improper Neutralization of Special Elements used in an SQL Command ( SQL Injection ) vulnerability in SonicWall GMS and Analytics".
The severity of CVE-2023-34133 is high with a value of 7.5.
SonicWall GMS versions 9.3.2-SP1 and earlier, and SonicWall Analytics version 2.5.0.4-r7 are affected by CVE-2023-34133.
An unauthenticated attacker can exploit CVE-2023-34133 by using SQL injection techniques to extract sensitive information from the application database.