CVE-2023-34134: SonicWall Analytics

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

Exposure of sensitive information to an unauthorized actor vulnerability in SonicWall GMS and Analytics allows authenticated attacker to read administrator password hash via a web service call. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

Affected products

  • SonicWall Analytics: up to and including 2.5.0.4-r7
  • SonicWall Global Management System: before 9.3.2 (fixed in 9.3.2); version 9.3.2 only

Published 2023-07-13. Last modified 2026-06-17.