Password in Configuration File in SonicWall GMS and SonicWall Analytics - CVE-2023-34128
Published: July 18, 2023
Vulnerability identifier: #VU78336
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34128
CWE-ID: CWE-260
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to the Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file, which leads to security restrictions bypass and privilege escalation.
Affected software
SonicWall GMS
SonicWall Analytics
SonicWall Analytics
How to mitigate CVE-2023-34128
Install updates from vendor's website.
SonicWall GMS - update to 9.3-9330
SonicWall Analytics - update to 2.5.2-R9
SonicWall Analytics - update to 2.5.2-R9