CVE-2023-34137: SonicWall Analytics

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

SonicWall GMS and Analytics CAS Web Services application use static values for authentication without proper checks leading to authentication bypass vulnerability. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

Affected products

  • SonicWall Analytics: up to and including 2.5.0.4-r7
  • SonicWall Global Management System: before 9.3.2 (fixed in 9.3.2); version 9.3.2 only

Published 2023-07-13. Last modified 2026-06-17.