Vulnerability record · CVE-2023-34133 · published 13 July 2023
CVE-2023-34133: SonicWall GMS and Analytics SQL Injection Allows Unauthenticated Data Theft
Sonicwall · Analytics
SonicWall GMS (9.3.2-SP1 and earlier) and Analytics (2.5.0.4-R7 and earlier) contain a SQL injection flaw (CWE-89) that can be triggered without authentication. A remote attacker can inject SQL into application input to read sensitive data from the underlying database, which may include credentials or configuration secrets.
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-accessible SQL injection with high confidentiality impact and very high EPSS probability warrants urgent patching despite no KEV listing.
What it is
SonicWall GMS (9.3.2-SP1 and earlier) and Analytics (2.5.0.4-R7 and earlier) contain a SQL injection flaw (CWE-89) that can be triggered without authentication. A remote attacker can inject SQL into application input to read sensitive data from the underlying database, which may include credentials or configuration secrets.
Impact
An unauthenticated attacker can extract sensitive information from the application database, potentially exposing credentials, configuration data, or other stored secrets. The CVSS vector shows high confidentiality impact with no integrity or availability impact.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), so it can be exploited directly against the exposed GMS or Analytics interface. No authentication is needed per the description and CVSS vector.
Exploitation
The CVE is not listed in CISA KEV, but EPSS is very high (0.72579, 99.4th percentile), indicating a strong likelihood of exploitation activity. A public Packet Storm reference mentions remote code execution for SonicWall GMS, though the record does not confirm exploit code specific to this SQL injection.
What to do
- Upgrade GMS to a version later than 9.3.2-SP1 and Analytics to a version later than 2.5.0.4-R7 per the SonicWall advisory.
- Restrict network access to GMS and Analytics management interfaces to trusted management networks or VPN only.
- Enable and review database and application logs for anomalous SQL query patterns or unexpected data access.
- Apply vendor-recommended hardening and monitor SonicWall PSIRT advisories for updated guidance.
Detection
- Monitor web and application logs for SQL injection patterns such as UNION SELECT, stacked queries, or time-based payloads against GMS/Analytics endpoints.
- Alert on unexpected outbound database connections or large data reads from the GMS/Analytics database service.
- Review authentication and access logs for unauthenticated requests to application endpoints that normally require login.
- Use WAF or IDS signatures tuned to SQL injection against SonicWall GMS/Analytics paths and correlate with EPSS-high CVE activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-34133 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-34133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.