Description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Published: 2023-07-13
Score: 8.8 High
EPSS: 90.6% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Sonicwall Analytics Global Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2025-04-23T16:20:27.112Z

Reserved: 2023-05-25T22:45:46.851Z

Link: CVE-2023-34127

cve-icon Vulnrichment

Updated: 2024-08-02T16:01:53.890Z

cve-icon NVD

Status : Modified

Published: 2023-07-13T01:15:08.893

Modified: 2025-04-23T17:16:33.140

Link: CVE-2023-34127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses