Known vulnerabilities in SonicWall Analytics

Vendor: SonicWall
Software CPE: cpe:2.3:a:sonicwall:sonicwall_analytics:*:*:*:*:*:*:*:*
Total vulnerabilities: 17
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SonicWall Analytics SonicWall Analytics is affected by 17 known vulnerabilities: 1 critical, 5 high, 10 medium, 1 low Critical High Medium Low

Vulnerabilities (17)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU78345 - Authentication Bypass by Primary Weakness
CVE-2023-34137
CWE-305 High
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78344 - Unrestricted Upload of File with Dangerous Type
CVE-2023-34136
CWE-434 High
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78343 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-34135
CWE-22 Medium
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78342 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34134
CWE-200 Medium
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78341 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2023-34133
CWE-89 High
Available
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78340 - Use of Password Hash Instead of Password for Authentication
CVE-2023-34132
CWE-836 Medium
Available
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78339 - Exposure of sensitive information to an unauthorized actor
CVE-2023-34131
CWE-200 Medium
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78338 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2023-34130
CWE-327 Medium
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78337 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-34129
CWE-22 Medium
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78336 - Password in Configuration File
CVE-2023-34128
CWE-260 Low
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78335 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-34127
CWE-78 Medium
Available
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78334 - Unrestricted Upload of File with Dangerous Type
CVE-2023-34126
CWE-434 Medium
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78332 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-34125
CWE-22 Medium
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78331 - Improper Authentication
CVE-2023-34124
CWE-287 High
Available
No
2.5.2-R9 18.07.2023 SB2023071818
#VU78330 - Use of Hard-coded Cryptographic Key
CVE-2023-34123
CWE-321 Medium
No
No
2.5.2-R9 18.07.2023 SB2023071818
#VU65714 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-22280
CWE-89 High
No
No
2.5.0.3-2520-Hotfix1 22.07.2022 SB2022072213
SB2022072214
#VU55689 - Configuration
CVE-2021-20032
CWE-16 Critical
No
No
2.5.2519 10.08.2021 SB2021081009