First published: Thu Jul 13 2023(Updated: )
Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Credit: PSIRT@sonicwall.com PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall Analytics | <=2.5.0.4-r7 | |
SonicWALL Global Management System | <9.3.2 | |
SonicWALL Global Management System | =9.3.2 | |
SonicWALL Global Management System | =9.3.2-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-34136 is critical with a score of 9.8.
CVE-2023-34136 allows an unauthenticated attacker to upload files to a restricted location not controlled by the attacker in SonicWall GMS: 9.3.2-SP1 and earlier versions, and Analytics: 2.5.0.4-R7 and earlier versions.
CVE-2023-34136 affects SonicWall GMS: 9.3.2-SP1 and earlier versions, and Analytics: 2.5.0.4-R7 and earlier versions.
To fix CVE-2023-34136, SonicWall GMS should be updated to version 9.3.2-SP2 or higher, and Analytics should be updated to version 2.5.0.4-R8 or higher.
More information about CVE-2023-34136 can be found at the following references: [link1](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010) and [link2](https://www.sonicwall.com/support/notices/230710150218060).