Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-34129


Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote attacker to traverse the directory and extract arbitrary files using Zip Slip method to any location on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.


Published

2023-07-13T02:15:09.303

Last Modified

2024-11-21T08:06:36.537

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sonicwall analytics ≤ 2.5.0.4-r7 Yes
Application sonicwall global_management_system < 9.3.2 Yes
Application sonicwall global_management_system 9.3.2 Yes
Application sonicwall global_management_system 9.3.2 Yes

References