← Vulnerability feed

Vulnerability record · CVE-2023-34133 · published 13 July 2023

CVE-2023-34133: SonicWall GMS and Analytics SQL Injection Allows Unauthenticated Data Theft

Sonicwall · Analytics

SonicWall GMS (9.3.2-SP1 and earlier) and Analytics (2.5.0.4-R7 and earlier) contain a SQL injection flaw (CWE-89) that can be triggered without authentication. A remote attacker can inject SQL into application input to read sensitive data from the underlying database, which may include credentials or configuration secrets.

7.5 CVSS 3.1 High EPSS 73% · top 0.6% CWE-89 · SQL injection
7.5CVSS 3.1 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated network-accessible SQL injection with high confidentiality impact and very high EPSS probability warrants urgent patching despite no KEV listing.

What it is

SonicWall GMS (9.3.2-SP1 and earlier) and Analytics (2.5.0.4-R7 and earlier) contain a SQL injection flaw (CWE-89) that can be triggered without authentication. A remote attacker can inject SQL into application input to read sensitive data from the underlying database, which may include credentials or configuration secrets.

Impact

An unauthenticated attacker can extract sensitive information from the application database, potentially exposing credentials, configuration data, or other stored secrets. The CVSS vector shows high confidentiality impact with no integrity or availability impact.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), so it can be exploited directly against the exposed GMS or Analytics interface. No authentication is needed per the description and CVSS vector.

Exploitation

The CVE is not listed in CISA KEV, but EPSS is very high (0.72579, 99.4th percentile), indicating a strong likelihood of exploitation activity. A public Packet Storm reference mentions remote code execution for SonicWall GMS, though the record does not confirm exploit code specific to this SQL injection.

What to do

  • Upgrade GMS to a version later than 9.3.2-SP1 and Analytics to a version later than 2.5.0.4-R7 per the SonicWall advisory.
  • Restrict network access to GMS and Analytics management interfaces to trusted management networks or VPN only.
  • Enable and review database and application logs for anomalous SQL query patterns or unexpected data access.
  • Apply vendor-recommended hardening and monitor SonicWall PSIRT advisories for updated guidance.

Detection

  • Monitor web and application logs for SQL injection patterns such as UNION SELECT, stacked queries, or time-based payloads against GMS/Analytics endpoints.
  • Alert on unexpected outbound database connections or large data reads from the GMS/Analytics database service.
  • Review authentication and access logs for unauthenticated requests to application endpoints that normally require login.
  • Use WAF or IDS signatures tuned to SQL injection against SonicWall GMS/Analytics paths and correlate with EPSS-high CVE activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-34133 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2016-2396Sonicwall analyzer command injection vulnerabilityThe GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authen…EPSS 4.7%9.8CVE-2023-34132Sonicwall analytics vulnerabilityUse of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue aff…EPSS 7.7%9.8CVE-2023-34136Sonicwall analytics unrestricted file upload vulnerabilityVulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker.…EPSS 0.80%9.8CVE-2023-34137Sonicwall analytics improper authentication vulnerabilitySonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass …EPSS 1.0%9.8CVE-2023-34130Sonicwall analytics broken cryptographic algorithm vulnerabilitySonicWall GMS and Analytics use outdated Tiny Encryption Algorithm (TEA) with a hardcoded key to encrypt sensitive data. This issue affects GMS: 9.3.…EPSS 0.31%9.8CVE-2023-34124SonicWall GMS and Analytics Web Services authentication bypassThe authentication mechanism in SonicWall GMS and Analytics Web Services performs insufficient checks, allowing an unauthenticated attacker to bypass…EPSS 50%analysed9.8CVE-2023-34128Sonicwall analytics insufficiently protected credentials vulnerabilityTomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…EPSS 0.71%9.8CVE-2022-22280Sonicwall analytics sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.…EPSS 9.5%

Source: NIST National Vulnerability Database (record CVE-2023-34133), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.