peter bassill · operator
$ cve CVE-2023-34132 JSON

CVE-2023-34132

9.8
CRITICAL · CVSS 3.1 · EPSS 7.7% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.68% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-836
On CISA KEVno
Public exploitnone known
Published2023-07-13
Last modified2026-06-17

Affected (2)

VendorProduct
sonicwallanalytics
sonicwallglobal management system

References

→ the Explorer  ·  watch your stack  ·  NVD