8.8

CVE-2023-34129

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote attacker to traverse the directory and extract arbitrary files using Zip Slip method to any location on the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sonicwall ≫ Analytics Version <= 2.5.0.4-r7
Sonicwall ≫ Global Management System Version < 9.3.2
Sonicwall ≫ Global Management System Version 9.3.2 Update -
Sonicwall ≫ Global Management System Version 9.3.2 Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 41.16% 0.985
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010
Vendor Advisory
https://www.sonicwall.com/support/notices/230710150218060
Vendor Advisory