Path traversal in SonicWall GMS and SonicWall Analytics - CVE-2023-34129

 

Path traversal in SonicWall GMS and SonicWall Analytics - CVE-2023-34129

Published: July 18, 2023 / Updated: August 22, 2023


Vulnerability identifier: #VU78337
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-34129
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote user can traverse the directory and extract arbitrary files using Zip Slip method to any location on the underlying filesystem with root privileges.


Affected software

SonicWall GMS
SonicWall Analytics

How to mitigate CVE-2023-34129

Install update from vendor's website.

SonicWall GMS - update to 9.3-9330
SonicWall Analytics - update to 2.5.2-R9

External References

Related Security Bulletins