Global Management System

Vendor:

First CVE: Dec 9, 2013 · Active for 12 years

32
Total CVEs
More Total CVEs than 97% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 74% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Global Management System over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 9, 2013
12 years ago
Most Recent CVE
Jul 13, 2023
1,111 days ago

CVE Severity & Scoring

Global Management System32 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local1 (3.1%)
Network26 (81.3%)
Unknown5 (15.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (81.3%)
High1 (3.1%)
Unknown5 (15.6%)
User Interaction
None26 (81.3%)
Unknown5 (15.6%)
Required1 (3.1%)
Privileges Required
Low9 (28.1%)
High0 (0.0%)
None18 (56.3%)
Unknown5 (15.6%)

Top CVEs

Signals from CVEs in this product scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1,
Feb 11, 20209.889NOYES
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to
Jul 13, 20238.883NOYES
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SonicWall GMS and Analytics allows an unauthenticated attacker to extract sens
Jul 13, 20237.578NOYES
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects GMS: 9.3.2-SP1 and earlier vers
Jul 13, 20239.873NOYES
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori
May 22, 20185.565NOYES
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal Management Appliance (UMA) 5.1,
Feb 11, 20209.852NOYES
The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA before 7.2 SP2 allows remote aut
Nov 25, 20149.050NOYES
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote attacker to traverse the
Jul 13, 20238.846NONO
Use of password hash instead of password for authentication vulnerability in SonicWall GMS and Analytics allows Pass-the-Hash attacks. This issue affects GMS: 9.3.2-SP1 and earlier
Jul 13, 20239.840NOYES
Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.3.1-SP2-Hotfix1, Analytics On-P
Jul 29, 20229.835NONO

Exploit Exposure

Signals from CVEs in this product scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
18.8% of CVEs· 98th percentile
Nuclei
2 CVEs
6.2% of CVEs· 97th percentile
ExploitDB
4 CVEs
12.5% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (32 CVEs).

Media Mentions

Signals from CVEs in this product scope (32 CVEs).

Top CNAs Publishing CVEs For Global Management System

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.3.2158.317.9%04
9.3.119.89.4%00
9.319.83.7%00
9.128.91.2%00
9.028.91.2%00
8.728.91.2%00
8.628.91.2%00
8.519.81.1%00
8.428.91.2%00
8.129.85.6%00
8.029.85.6%00
7.239.611.7%01
7.124.03.3%01
7.046.324.5%03
6.029.856.3%02
5.129.856.3%02
5.029.856.3%02
4.129.856.3%02