← Vulnerability feed

Vulnerability record · CVE-2023-34127 · published 13 July 2023

CVE-2023-34127: SonicWall GMS and Analytics OS command injection to root

Sonicwall · Analytics

SonicWall GMS and Analytics contain an OS command injection flaw (CWE-78) that lets an authenticated attacker run arbitrary commands with root privileges. The affected versions are GMS 9.3.2-SP1 and earlier and Analytics 2.5.0.4-R7 and earlier. Because the resulting code runs as root, a single authenticated foothold can fully compromise the appliance.

8.8 CVSS 3.1 High EPSS 86% · top 0.3% CWE-78 · OS command injection
8.8CVSS 3.1 base score
86%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.8 with root-level code execution and a very high EPSS score, though it requires authenticated access and is not in KEV.

What it is

SonicWall GMS and Analytics contain an OS command injection flaw (CWE-78) that lets an authenticated attacker run arbitrary commands with root privileges. The affected versions are GMS 9.3.2-SP1 and earlier and Analytics 2.5.0.4-R7 and earlier. Because the resulting code runs as root, a single authenticated foothold can fully compromise the appliance.

Impact

An attacker with valid credentials gains arbitrary code execution as root on the GMS or Analytics host, allowing full control of the system, its data and any managed devices or credentials it holds.

Attack surface

The vulnerability is network-reachable (AV:N) and requires low-privileged authentication (PR:L) with no user interaction (UI:N). It is reached through the GMS or Analytics web interface by a logged-in user.

Exploitation

Not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.865 (99.7th percentile), and a public Packet Storm remote code execution write-up exists, indicating exploit interest and likely availability.

What to do

  • Upgrade GMS to a version later than 9.3.2-SP1 and Analytics to a version later than 2.5.0.4-R7 per the SonicWall PSIRT advisory SNWLID-2023-0010.
  • Restrict network access to GMS and Analytics management interfaces to trusted administrative networks only.
  • Enforce least privilege and strong authentication for GMS/Analytics accounts, and audit for unnecessary or shared logins.
  • Monitor and rotate any credentials or device secrets stored or managed by the affected appliances.
  • If immediate patching is not possible, isolate the appliance and apply compensating network controls until upgrade.

Detection

  • Review GMS/Analytics logs and web server logs for suspicious command or shell metacharacter patterns in requests from authenticated sessions.
  • Monitor for unexpected child processes spawned by the GMS/Analytics web service, especially shells or commands running as root.
  • Alert on anomalous outbound network connections or file writes originating from the GMS/Analytics host.
  • Audit authentication logs for unusual or off-hours logins to GMS/Analytics administrative accounts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-34127 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2016-2396Sonicwall analyzer command injection vulnerabilityThe GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authen…EPSS 4.7%9.8CVE-2023-34132Sonicwall analytics vulnerabilityUse of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue aff…EPSS 7.7%9.8CVE-2023-34136Sonicwall analytics unrestricted file upload vulnerabilityVulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker.…EPSS 0.80%9.8CVE-2023-34137Sonicwall analytics improper authentication vulnerabilitySonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass …EPSS 1.0%9.8CVE-2023-34130Sonicwall analytics broken cryptographic algorithm vulnerabilitySonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.…EPSS 0.31%9.8CVE-2023-34124SonicWall GMS and Analytics Web Services authentication bypassThe authentication mechanism in SonicWall GMS and Analytics Web Services performs insufficient checks, allowing an unauthenticated attacker to bypass…EPSS 50%analysed9.8CVE-2023-34128Sonicwall analytics insufficiently protected credentials vulnerabilityTomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…EPSS 0.71%9.8CVE-2022-22280Sonicwall analytics sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.…EPSS 9.5%

Source: NIST National Vulnerability Database (record CVE-2023-34127), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.