Sonicwall

Global Management System

36 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.17%
  • Veröffentlicht 11.08.2026 20:10:39
  • Zuletzt bearbeitet 28.08.2026 18:58:27

An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.

Medienbericht
  • EPSS 1.05%
  • Veröffentlicht 11.08.2026 20:08:56
  • Zuletzt bearbeitet 28.08.2026 18:58:27

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

  • EPSS 0.88%
  • Veröffentlicht 01.05.2024 19:15:22
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Use of hard-coded password in the GMS ECM endpoint leading to authentication bypass vulnerability. This issue affects GMS: 9.3.4 and earlier versions.

  • EPSS 0.62%
  • Veröffentlicht 01.05.2024 18:15:17
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure of sensitive information. This issue affects GMS: 9.3.4 and earlier versions.

  • EPSS 72.77%
  • Veröffentlicht 13.07.2023 03:15:09
  • Zuletzt bearbeitet 23.04.2025 17:16:33

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GM...

  • EPSS 0.83%
  • Veröffentlicht 13.07.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:36

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker to access restricted web pages. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 ...

  • EPSS 7.68%
  • Veröffentlicht 13.07.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:36

Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

  • EPSS 1.12%
  • Veröffentlicht 13.07.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:37

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authenticated attacker to read administrator password hash via a web service call. This issue affects GMS: 9.3.2-SP1 and earlier versions; ...

  • EPSS 1.57%
  • Veröffentlicht 13.07.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:37

Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file system via web service. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 ...

  • EPSS 0.8%
  • Veröffentlicht 13.07.2023 03:15:09
  • Zuletzt bearbeitet 21.11.2024 08:06:37

Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.