8.8
CVSSv3

CVE-2023-34129

Published: 13/07/2023 Updated: 20/07/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote malicious user to traverse the directory and extract arbitrary files using Zip Slip method to any location on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and previous versions versions; Analytics: 2.5.0.4-R7 and previous versions versions.

Vulnerable Product Search on Vulmon Subscribe to Product

sonicwall global management system

sonicwall analytics

sonicwall global management system 9.3.2

Vendor Advisories

Check Point Reference: CPAI-2023-1570 Date Published: 13 Mar 2024 Severity: High ...