Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote attacker to traverse the directory and extract arbitrary files using Zip Slip method to any location on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published: 2023-07-13T01:03:51.894Z

Updated: 2024-08-02T16:01:54.159Z

Reserved: 2023-05-25T22:45:46.851Z

Link: CVE-2023-34129

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-07-13T02:15:09.303

Modified: 2023-07-20T19:14:47.987

Link: CVE-2023-34129

cve-icon Redhat

No data.