{"cve":"CVE-2023-34124","epss":{"score":0.50477},"mitre":{"cpes":[],"created":"2023-07-13T00:14:16.861000+00:00","description":"The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{},"cvssV4_0":{}},"mitre_repo_path":"cves/2023/34xxx/CVE-2023-34124.json","references":["http://packetstormsecurity.com/files/174571/Sonicwall-GMS-9.9.9320-Remote-Code-Execution.html","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010","https://www.sonicwall.com/support/notices/230710150218060"],"title":null,"updated":"2025-04-08T15:23:32.589000+00:00","vendors":[],"weaknesses":["CWE-305"]},"nvd":{"cpes":["cpe:2.3:a:sonicwall:analytics:*:*:*:*:*:*:*:*","cpe:2.3:a:sonicwall:global_management_system:*:*:*:*:*:*:*:*","cpe:2.3:a:sonicwall:global_management_system:9.3.2:-:*:*:*:*:*:*","cpe:2.3:a:sonicwall:global_management_system:9.3.2:sp1:*:*:*:*:*:*"],"created":"2023-07-13T01:15:08.723000+00:00","description":"The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{}},"nvd_repo_path":"2023/CVE-2023-34124.json","references":["http://packetstormsecurity.com/files/174571/Sonicwall-GMS-9.9.9320-Remote-Code-Execution.html","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010","https://www.sonicwall.com/support/notices/230710150218060"],"title":null,"updated":"2026-06-17T06:02:56.723000+00:00","vendors":["sonicwall","sonicwall$PRODUCT$analytics","sonicwall$PRODUCT$global_management_system"],"weaknesses":["CWE-287","CWE-305"]},"opencve":{"changes":[{"created":"2024-10-30T19:15:00+00:00","data":[{"details":{"added":{"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"removed":{},"updated":{}},"type":"metrics"}],"id":"a16fa32a-3fa7-408a-9521-fc7ff04d60b6"},{"created":"2025-02-13T17:00:00+00:00","data":[{"details":{"new":"The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.","old":"The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.\n\n"},"type":"description"}],"id":"a3d8a53b-0c07-4750-a90b-c8610275a944"},{"created":"2025-07-16T13:45:00+00:00","data":[{"details":{"added":{},"removed":{},"updated":{"epss":{"new":{"score":0.91536},"old":{"score":0.92251}}}},"type":"metrics"}],"id":"d333d2d5-36fc-4984-94e4-03afb235e07a"}],"cpes":{"data":["cpe:2.3:a:sonicwall:analytics:*:*:*:*:*:*:*:*","cpe:2.3:a:sonicwall:global_management_system:*:*:*:*:*:*:*:*","cpe:2.3:a:sonicwall:global_management_system:9.3.2:-:*:*:*:*:*:*","cpe:2.3:a:sonicwall:global_management_system:9.3.2:sp1:*:*:*:*:*:*"],"providers":["nvd"]},"created":{"data":"2023-07-13T00:14:16.861000+00:00","provider":"mitre"},"description":{"data":"The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.","provider":"mitre"},"metrics":{"cvssV2_0":{"data":{},"provider":null},"cvssV3_0":{"data":{},"provider":null},"cvssV3_1":{"data":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"provider":"vulnrichment"},"cvssV4_0":{"data":{},"provider":null},"epss":{"data":{"score":0.50477},"provider":"first"},"kev":{"data":{},"provider":null},"ssvc":{"data":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"},"provider":"vulnrichment"},"threat_severity":{"data":null,"provider":null}},"references":{"data":["http://packetstormsecurity.com/files/174571/Sonicwall-GMS-9.9.9320-Remote-Code-Execution.html","https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0010","https://www.sonicwall.com/support/notices/230710150218060"],"providers":["mitre","nvd"]},"title":{"data":null,"provider":null},"updated":{"data":"2025-04-08T16:15:24.530000+00:00","provider":"nvd"},"vendors":{"data":["sonicwall","sonicwall$PRODUCT$analytics","sonicwall$PRODUCT$global_management_system"],"providers":["nvd"]},"weaknesses":{"data":["CWE-287","CWE-305"],"providers":["mitre","nvd"]}},"vulnrichment":{"cpes":[],"created":"2023-07-13T00:14:16.861000+00:00","description":"The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.","metrics":{"cvssV2_0":{},"cvssV3_0":{},"cvssV3_1":{"score":9.8,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"cvssV4_0":{},"kev":{},"ssvc":{"options":{"Automatable":"yes","Exploitation":"none","Technical Impact":"total"},"version":"2.0.3"}},"references":[],"title":null,"updated":"2024-10-30T18:53:39.517000+00:00","vendors":[],"vulnrichment_repo_path":"2023/34xxx/CVE-2023-34124.json","weaknesses":[]}}