HTTP: SonicWall GMS and Analytics performDownloadTask Directory Traversal

This signature detects attempts to exploit a known vulnerability against SonicWall GMS and Analytics performDownloadTask. A successful attack can lead to directory traversal and arbitrary code execution.

Extended Description

Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root privileges. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: 2.5.0.4-R7 and earlier versions.

Affected Products

Sonicwall global_management_system

Short Name
HTTP:DIR:SONICWL-GMS-ANTYSDT
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Analytics CVE-2023-34125 CVE-2023-34129 Directory GMS SonicWall Traversal and performDownloadTask
Release Date
09/06/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3635
False Positive
Unknown
Vendors

Sonicwall

Found a potential security threat?