CVE-2023-34133
SonicWall analytics Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Record summary
CVE-2023-34133 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 16, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
AnalyticsBrowse SonicWall / AnalyticsDefault status: unknown | CVE List, VulnCheck | 2.5.0.4-R7 and earlier versions | affected |
Default status: unknown | CVE List | 9.3.2-SP1 and earlier versions | affected |
Proofs of concept
1Catalogued exploits
MetasploitSonicwallMetasploit exploitby Ron Bowes <rbowes@rapid7.com> +1 moreNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHSonicWall GMS and Analytics - SQL InjectionCVSS 7.5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Impact
Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the target system.
Remediation
Apply the latest security patches or updates provided by SonicWall to mitigate this vulnerability.
Source: ProjectDiscovery