SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-34131

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker to access restricted web pages.

MEDIUM 5.3EPSS 0.83%

Does this matter?

Lower severity and a low EPSS score (0.83%). Track it; it rarely justifies an emergency change on its own.

Description

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics enables an unauthenticated attacker to access restricted web pages. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
0.83% probability · 55th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
sonicwall/analytics · sonicwall/global management system
Source
PSIRT@sonicwall.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.