High severity7.5NVD Advisory· Published Jul 13, 2023· Updated Jun 17, 2026
CVE-2023-34133
CVE-2023-34133
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sensitive information from the application database. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.
Affected products
8- Range: <=2.5.0.4-R7
cpe:2.3:a:sonicwall:global_management_system:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:sonicwall:global_management_system:*:*:*:*:*:*:*:*range: <9.3.2
- cpe:2.3:a:sonicwall:global_management_system:9.3.2:-:*:*:*:*:*:*
- cpe:2.3:a:sonicwall:global_management_system:9.3.2:sp1:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3News mentions
2- Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterTenable Blog · Aug 26, 2026
- Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your PerimeterSentinelOne Labs · Aug 26, 2026