📦 Analytics

by Sonicwall

🔍 What is Analytics?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-34132

CRITICAL CVSS 9.8 Jul 13, 2023

This vulnerability in SonicWall GMS and Analytics allows attackers to use password hashes instead of actual passwords for authentication, enabling Pass-the-Hash attacks. This affects SonicWall GMS ver...

CVE-2023-34136

CRITICAL CVSS 9.8 Jul 13, 2023

CVE-2023-34136 is a critical vulnerability in SonicWall GMS and Analytics that allows unauthenticated attackers to upload arbitrary files to restricted locations. This can lead to remote code executio...

CVE-2023-34130

CRITICAL CVSS 9.8 Jul 13, 2023

SonicWall GMS and Analytics use an outdated, weak encryption algorithm (TEA) with a hardcoded key to protect sensitive data. This allows attackers to decrypt sensitive information stored or transmitte...

CVE-2023-34124

CRITICAL CVSS 9.8 Jul 13, 2023

CVE-2023-34124 is an authentication bypass vulnerability in SonicWall GMS and Analytics Web Services that allows attackers to gain unauthorized access without valid credentials. This affects SonicWall...

CVE-2023-34128

CRITICAL CVSS 9.8 Jul 13, 2023

This vulnerability involves hardcoded Tomcat application credentials in SonicWall GMS and Analytics configuration files. Attackers who can access these files can gain administrative access to the Tomc...

CVE-2022-22280

CRITICAL CVSS 9.8 Jul 29, 2022

This is an unauthenticated SQL injection vulnerability in SonicWall GMS and Analytics On-Prem products. Attackers can execute arbitrary SQL commands without authentication, potentially compromising th...

CVE-2021-20032

CRITICAL CVSS 9.8 Aug 10, 2021

SonicWall Analytics 2.5 On-Prem has a Java Debug Wire Protocol (JDWP) interface misconfiguration that allows remote attackers to execute arbitrary code without authentication. This vulnerability affec...

CVE-2023-34129

HIGH CVSS 8.8 Jul 13, 2023

This path traversal vulnerability in SonicWall GMS and Analytics allows authenticated attackers to extract arbitrary files from the underlying filesystem using Zip Slip techniques. Attackers can write...

CVE-2023-34126

HIGH CVSS 8.8 Jul 13, 2023

This vulnerability allows authenticated attackers to upload arbitrary files with root privileges on SonicWall GMS and Analytics systems. Attackers could potentially execute malicious code, modify syst...

CVE-2023-34123

HIGH CVSS 7.5 Jul 13, 2023

This CVE describes a hard-coded cryptographic key vulnerability in SonicWall GMS and Analytics products. Attackers who discover the embedded key could decrypt sensitive data or forge authentication to...