CVE-2023-34137: Critical severity SonicWall Analytics vulnerability
SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass vulnerability. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-34137?
The severity of CVE-2023-34137 is critical with a CVSS score of 9.8.
Which versions of SonicWall GMS and Analytics are affected by CVE-2023-34137?
SonicWall GMS versions 9.3.2-SP1 and earlier, and Analytics versions 2.5.0.4-R7 and earlier are affected by CVE-2023-34137.
What is the vulnerability description of CVE-2023-34137?
CVE-2023-34137 is an authentication bypass vulnerability in SonicWall GMS and Analytics CAS Web Services application, caused by the use of static values for authentication without proper checks.
How can I fix CVE-2023-34137?
To fix CVE-2023-34137, update SonicWall GMS to version 9.3.2-SP2 or later, and update Analytics to version 2.5.0.4-R8 or later.
Are there any references for CVE-2023-34137?
Yes, you can find more information about CVE-2023-34137 in the SonicWall PSIRT advisory (https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010) and the SonicWall support notices (https://www.sonicwall.com/support/notices/230710150218060).