Path Traversal Vulnerability in SonicWall GMS and Analytics
CVE-2023-34129
8.8HIGH
Summary
A vulnerability exists in SonicWall GMS and Analytics due to insufficient restrictions on pathname access, enabling an authenticated remote attacker to exploit this weakness using a 'Zip Slip' technique. This flaw enables the extraction of arbitrary files to any location on the underlying filesystem, potentially granting root privileges. The issue impacts specific versions of both GMS and Analytics, highlighting the critical need for users to review and mitigate this risk.
Affected Version(s)
Analytics 2.5.0.4-R7 and earlier versions
GMS 9.3.2-SP1 and earlier versions
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved