Path traversal in SonicWall GMS and SonicWall Analytics - CVE-2023-34129
Published: July 18, 2023 / Updated: August 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote user can traverse the directory and extract arbitrary files using Zip Slip method to any location on the underlying filesystem with root privileges.
Affected software
SonicWall Analytics
How to mitigate CVE-2023-34129
SonicWall Analytics - update to 2.5.2-R9