SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass vulnerability. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010 | Vendor Advisory |
https://www.sonicwall.com/support/notices/230710150218060 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-07-13 03:15
Updated : 2023-07-25 14:04
NVD link : CVE-2023-34137
Mitre link : CVE-2023-34137
CVE.ORG link : CVE-2023-34137
JSON object : View
Products Affected
sonicwall
- global_management_system
- analytics