← back
CVE-2023-34127highCWE-78

CVE-2023-34127

58Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.8epss 86%
from disclosure to weapon0 days
Published on NVDJul 13
metasploitJul 12
exploitation probability
86%top 1% of all CVEs
observed exploitation
nono source reports it
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H