Vulnerability record · CVE-2023-34124 · published 13 July 2023
CVE-2023-34124: SonicWall GMS and Analytics Web Services authentication bypass
Sonicwall · Analytics
The authentication mechanism in SonicWall GMS and Analytics Web Services performs insufficient checks, allowing an unauthenticated attacker to bypass authentication. The flaw affects GMS 9.3.2-SP1 and earlier and Analytics 2.5.0.4-R7 and earlier, and carries a critical CVSS score of 9.8.
Description
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable authentication bypass with CVSS 9.8, high EPSS, and a public RCE exploit makes this an urgent patch target.
What it is
The authentication mechanism in SonicWall GMS and Analytics Web Services performs insufficient checks, allowing an unauthenticated attacker to bypass authentication. The flaw affects GMS 9.3.2-SP1 and earlier and Analytics 2.5.0.4-R7 and earlier, and carries a critical CVSS score of 9.8.
Impact
An attacker gains full access to the affected web services without valid credentials, with high confidentiality, integrity and availability impact. A public exploit reference indicates remote code execution is achievable on GMS.
Attack surface
Reachable over the network via the Web Services interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed GMS or Analytics instance is a candidate target.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.50 (98.9th percentile) and a public Packet Storm exploit for GMS remote code execution exists, indicating active interest and available tooling.
What to do
- Apply the SonicWall vendor patches referenced in advisory SNWLID-2023-0010 and the associated support notice; upgrade GMS and Analytics to fixed versions.
- Restrict network access to GMS and Analytics Web Services to trusted management networks; do not expose them to the internet.
- Rotate credentials and review accounts on affected appliances for signs of unauthorized access before patching.
- Monitor vendor advisories for updated fixed versions if the current release does not cover your deployment.
Detection
- Review GMS and Analytics Web Services logs for authentication events that succeed without a preceding valid login or with anomalous source IPs.
- Alert on unexpected administrative actions, new accounts, or configuration changes on GMS/Analytics hosts.
- Hunt for exploitation attempts matching the public Packet Storm RCE proof-of-concept against exposed Web Services endpoints.
- Baseline and monitor outbound connections from GMS/Analytics appliances for command-and-control or lateral movement.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-34124 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-34124), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.