← Vulnerability feed

Vulnerability record · CVE-2023-34124 · published 13 July 2023

CVE-2023-34124: SonicWall GMS and Analytics Web Services authentication bypass

Sonicwall · Analytics

The authentication mechanism in SonicWall GMS and Analytics Web Services performs insufficient checks, allowing an unauthenticated attacker to bypass authentication. The flaw affects GMS 9.3.2-SP1 and earlier and Analytics 2.5.0.4-R7 and earlier, and carries a critical CVSS score of 9.8.

9.8 CVSS 3.1 Critical EPSS 50% · top 1.1% CWE-305 · CWE-305CWE-287 · Improper authentication
9.8CVSS 3.1 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable authentication bypass with CVSS 9.8, high EPSS, and a public RCE exploit makes this an urgent patch target.

What it is

The authentication mechanism in SonicWall GMS and Analytics Web Services performs insufficient checks, allowing an unauthenticated attacker to bypass authentication. The flaw affects GMS 9.3.2-SP1 and earlier and Analytics 2.5.0.4-R7 and earlier, and carries a critical CVSS score of 9.8.

Impact

An attacker gains full access to the affected web services without valid credentials, with high confidentiality, integrity and availability impact. A public exploit reference indicates remote code execution is achievable on GMS.

Attack surface

Reachable over the network via the Web Services interface with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet- or network-exposed GMS or Analytics instance is a candidate target.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.50 (98.9th percentile) and a public Packet Storm exploit for GMS remote code execution exists, indicating active interest and available tooling.

What to do

  • Apply the SonicWall vendor patches referenced in advisory SNWLID-2023-0010 and the associated support notice; upgrade GMS and Analytics to fixed versions.
  • Restrict network access to GMS and Analytics Web Services to trusted management networks; do not expose them to the internet.
  • Rotate credentials and review accounts on affected appliances for signs of unauthorized access before patching.
  • Monitor vendor advisories for updated fixed versions if the current release does not cover your deployment.

Detection

  • Review GMS and Analytics Web Services logs for authentication events that succeed without a preceding valid login or with anomalous source IPs.
  • Alert on unexpected administrative actions, new accounts, or configuration changes on GMS/Analytics hosts.
  • Hunt for exploitation attempts matching the public Packet Storm RCE proof-of-concept against exposed Web Services endpoints.
  • Baseline and monitor outbound connections from GMS/Analytics appliances for command-and-control or lateral movement.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-34124 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2016-2396Sonicwall analyzer command injection vulnerabilityThe GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authen…EPSS 4.7%9.8CVE-2023-34132Sonicwall analytics vulnerabilityUse of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue aff…EPSS 7.7%9.8CVE-2023-34136Sonicwall analytics unrestricted file upload vulnerabilityVulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker.…EPSS 0.80%9.8CVE-2023-34137Sonicwall analytics improper authentication vulnerabilitySonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass …EPSS 1.0%9.8CVE-2023-34130Sonicwall analytics broken cryptographic algorithm vulnerabilitySonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.…EPSS 0.31%9.8CVE-2023-34128Sonicwall analytics insufficiently protected credentials vulnerabilityTomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…EPSS 0.71%9.8CVE-2022-22280Sonicwall analytics sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.…EPSS 9.5%9.8CVE-2021-20032Sonicwall analytics vulnerabilitySonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vulnerability which potentially …EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2023-34124), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.