Global Management System
Vendor:
First CVE: Dec 9, 2013 · Active for 12 years
32
Total CVEs
More Total CVEs than 97% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Global Management System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 9, 2013
12 years ago
Most Recent CVE
Jul 13, 2023
1,111 days ago
CVE Severity & Scoring
Global Management System32 CVEs
25%
28%
44%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (3.1%)
Network26 (81.3%)
Unknown5 (15.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (81.3%)
High1 (3.1%)
Unknown5 (15.6%)
User Interaction
None26 (81.3%)
Unknown5 (15.6%)
Required1 (3.1%)
Privileges Required
Low9 (28.1%)
High0 (0.0%)
None18 (56.3%)
Unknown5 (15.6%)
Top CVEs
Signals from CVEs in this product scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-1359CRITICAL An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, | Feb 11, 2020 | 9.8 | 89 | NO | YES |
CVE-2023-34127HIGH Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to | Jul 13, 2023 | 8.8 | 83 | NO | YES |
CVE-2023-34133HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sens | Jul 13, 2023 | 7.5 | 78 | NO | YES |
CVE-2023-34124CRITICAL The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier vers | Jul 13, 2023 | 9.8 | 73 | NO | YES |
CVE-2018-3639MEDIUM Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori | May 22, 2018 | 5.5 | 65 | NO | YES |
CVE-2013-1360CRITICAL An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1, | Feb 11, 2020 | 9.8 | 52 | NO | YES |
CVE-2014-8420HIGH The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote aut | Nov 25, 2014 | 9.0 | 50 | NO | YES |
CVE-2023-34129HIGH Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote attacker to traverse the | Jul 13, 2023 | 8.8 | 46 | NO | NO |
CVE-2023-34132CRITICAL Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue affects GMS: 9.3.2-SP1 and earlier | Jul 13, 2023 | 9.8 | 40 | NO | YES |
CVE-2022-22280CRITICAL Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-P | Jul 29, 2022 | 9.8 | 35 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (32 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
18.8% of CVEs· 98th percentile
Nuclei
2 CVEs
6.2% of CVEs· 97th percentile
ExploitDB
4 CVEs
12.5% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (32 CVEs).
Media Mentions
Signals from CVEs in this product scope (32 CVEs).
Top CNAs Publishing CVEs For Global Management System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.3.2 | 15 | 8.3 | 17.9% | 0 | 4 |
| 9.3.1 | 1 | 9.8 | 9.4% | 0 | 0 |
| 9.3 | 1 | 9.8 | 3.7% | 0 | 0 |
| 9.1 | 2 | 8.9 | 1.2% | 0 | 0 |
| 9.0 | 2 | 8.9 | 1.2% | 0 | 0 |
| 8.7 | 2 | 8.9 | 1.2% | 0 | 0 |
| 8.6 | 2 | 8.9 | 1.2% | 0 | 0 |
| 8.5 | 1 | 9.8 | 1.1% | 0 | 0 |
| 8.4 | 2 | 8.9 | 1.2% | 0 | 0 |
| 8.1 | 2 | 9.8 | 5.6% | 0 | 0 |
| 8.0 | 2 | 9.8 | 5.6% | 0 | 0 |
| 7.2 | 3 | 9.6 | 11.7% | 0 | 1 |
| 7.1 | 2 | 4.0 | 3.3% | 0 | 1 |
| 7.0 | 4 | 6.3 | 24.5% | 0 | 3 |
| 6.0 | 2 | 9.8 | 56.3% | 0 | 2 |
| 5.1 | 2 | 9.8 | 56.3% | 0 | 2 |
| 5.0 | 2 | 9.8 | 56.3% | 0 | 2 |
| 4.1 | 2 | 9.8 | 56.3% | 0 | 2 |