← Vulnerability feed

Vulnerability record · CVE-2014-0332 · published 14 February 2014

CVE-2014-0332: Sonicwall global management system cross-site scripting vulnerability

Sonicwall · Global Management System

Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action.

4.3 CVSS 2.0 Medium EPSS 2.8% · top 14.2% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
2.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-0332 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2016-2396Sonicwall analyzer command injection vulnerabilityThe GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authen…EPSS 4.7%9.8CVE-2023-34137Sonicwall analytics improper authentication vulnerabilitySonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass …EPSS 1.0%9.8CVE-2023-34136Sonicwall analytics unrestricted file upload vulnerabilityVulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker.…EPSS 0.80%9.8CVE-2023-34132Sonicwall analytics vulnerabilityUse of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue aff…EPSS 7.7%9.8CVE-2023-34130Sonicwall analytics broken cryptographic algorithm vulnerabilitySonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.…EPSS 0.31%9.8CVE-2023-34128Sonicwall analytics insufficiently protected credentials vulnerabilityTomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…EPSS 0.71%9.8CVE-2023-34124SonicWall GMS and Analytics Web Services authentication bypassThe authentication mechanism in SonicWall GMS and Analytics Web Services performs insufficient checks, allowing an unauthenticated attacker to bypass…EPSS 50%analysed9.8CVE-2022-22280Sonicwall analytics sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.…EPSS 9.5%

Source: NIST National Vulnerability Database (record CVE-2014-0332), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.