← Back to browse · API

CVE-2023-34127

Severity
HIGH
CVSS
8.8
EPSS
0.86469
Risk score
65.46
CISA KEV
No
PoC
No
Published
2023-07-13
Modified
2025-04-23
First seen
2026-08-07
Aliases
EUVD-2023-38229, GHSA-J825-X83P-56G6
Products
SonicWall:Analytics 2.5.0.4-R7 and earlier versions, SonicWall:GMS 9.3.2-SP1 and earlier versions
Sources
euvd EUVD-2023-38229

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

References