Record summary

CVE-2023-34133 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 16, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unknown

CVE List, VulnCheck2.5.0.4-R7 and earlier versionsaffected

Default status: unknown

CVE List9.3.2-SP1 and earlier versionsaffected

Proofs of concept

1

Catalogued exploits

MetasploitSonicwallMetasploit exploitby Ron Bowes <rbowes@rapid7.com> +1 moreNot analyzed1 file

Ruby · linked to 4 vulnerabilities

Metasploit

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHSonicWall GMS and Analytics - SQL InjectionCVSS 7.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the target system.

Remediation

Apply the latest security patches or updates provided by SonicWall to mitigate this vulnerability.

WeaknessesCWE-89
Authorstheamanrawat
Template tagscve2023cvesonicwallsqliinjectionvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:sonicwall:analytics:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:"-1381126564"
FOFA: icon_hash="-1381126564"

Source: ProjectDiscovery

References

4