Password in Configuration File in SonicWall GMS and SonicWall Analytics - CVE-2023-34128

 

Password in Configuration File in SonicWall GMS and SonicWall Analytics - CVE-2023-34128

Published: July 18, 2023


Vulnerability identifier: #VU78336
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34128
CWE-ID: CWE-260
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges on the system.

The vulnerability exists due to the Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file, which leads to security restrictions bypass and privilege escalation.


Affected software

SonicWall GMS
SonicWall Analytics

How to mitigate CVE-2023-34128

Install updates from vendor's website.

SonicWall GMS - update to 9.3-9330
SonicWall Analytics - update to 2.5.2-R9

External References

Related Security Bulletins