CVE-2023-34136: SonicWall Analytics

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Vulnerability in SonicWall GMS and Analytics allows unauthenticated attacker to upload files to a restricted location not controlled by the attacker. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

Affected products

  • SonicWall Analytics: up to and including 2.5.0.4-r7
  • SonicWall Global Management System: before 9.3.2 (fixed in 9.3.2); version 9.3.2 only

Published 2023-07-13. Last modified 2026-06-17.