Impact
An unauthenticated command injection flaw in the SonicWall GMS Dispatcher Service allows an attacker to execute arbitrary system commands on the underlying operating system. The vulnerability arises when the service processes specially crafted requests without proper input validation, leading to remote code execution. This weakness can compromise confidentiality, integrity, and availability of the affected system, potentially giving attackers full control over the compromised device.
Affected Systems
SonicWall GMS 9.5.1 and all earlier releases of the GMS platform are affected. The flaw resides specifically within the Dispatcher Service component of the product.
Risk and Exploitability
The CVSS score of 9.4 classifies this as Critical, indicating a high likelihood of success and impact. The EPSS score is 1%, and the vulnerability is not listed in the CISA KEV catalog, meaning there is no confirmed exploitation evidence yet. The attack vector is remote, leveraging unauthenticated HTTP requests to the Dispatcher Service. Because the endpoint is reachable from external networks, the condition for exploitation is minimal, enabling an attacker to trigger the flaw with no prior credential or privilege.
OpenCVE Enrichment