Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
History

Wed, 23 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published: 2023-07-13T00:47:58.798Z

Updated: 2025-04-23T16:20:27.112Z

Reserved: 2023-05-25T22:45:46.851Z

Link: CVE-2023-34127

cve-icon Vulnrichment

Updated: 2024-08-02T16:01:53.890Z

cve-icon NVD

Status : Modified

Published: 2023-07-13T01:15:08.893

Modified: 2025-04-23T17:16:33.140

Link: CVE-2023-34127

cve-icon Redhat

No data.