CVE-2023-34136: Malicious File Upload
Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SonicWall GMSto a version that resolves this vulnerability.Fixed in 9.3.2-SP1 - Upgrade
Upgrade
SonicWall Analyticsto a version that resolves this vulnerability.Fixed in 2.5.0.4-R7
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34136?
The severity of CVE-2023-34136 is critical with a score of 9.8.
How does CVE-2023-34136 impact SonicWall GMS and Analytics?
CVE-2023-34136 allows an unauthenticated attacker to upload files to a restricted location not controlled by the attacker in SonicWall GMS: 9.3.2-SP1 and earlier versions, and Analytics: 2.5.0.4-R7 and earlier versions.
What software versions are affected by CVE-2023-34136?
CVE-2023-34136 affects SonicWall GMS: 9.3.2-SP1 and earlier versions, and Analytics: 2.5.0.4-R7 and earlier versions.
How can I fix CVE-2023-34136?
To fix CVE-2023-34136, SonicWall GMS should be updated to version 9.3.2-SP2 or higher, and Analytics should be updated to version 2.5.0.4-R8 or higher.
Where can I find more information about CVE-2023-34136?
More information about CVE-2023-34136 can be found at the following references: [link1](https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010) and [link2](https://www.sonicwall.com/support/notices/230710150218060).