Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in SonicWall GMS

SonicWall GMS contains multiple vulnerabilities allowing remote code execution with root privileges, privilege escalation, security bypass, and information disclosure.

The German Federal Office for Information Security (BSI) has reported multiple critical vulnerabilities within SonicWall GMS (Global Management System). These flaws enable attackers to perform a variety of malicious actions including privilege escalation, arbitrary code execution with root-level access, bypassing security controls, data manipulation, unauthorized information disclosure, and Cross-Site Scripting (XSS). These vulnerabilities represent a significant risk to the integrity and confidentiality of network management infrastructure. Organizations running SonicWall GMS should review vendor security advisories immediately to apply necessary patches or mitigations to prevent potential system compromise and lateral movement within the network.

Impact

Successful exploitation of these vulnerabilities allows an attacker to achieve full control over the affected GMS instance, including root-level code execution. This level of access grants the attacker the ability to exfiltrate sensitive network management data, modify system configurations, and pivot into the managed network segments, potentially impacting the entire managed infrastructure connected to the GMS server.

Recommendation

  • Monitor the official SonicWall support portal for the release of security patches corresponding to this advisory and apply them to all GMS instances immediately.
  • Restrict network access to the GMS management interface to authorized administrative segments only, ensuring it is not accessible from the public internet.
  • Audit GMS application logs for suspicious activity, such as unexpected administrative access or attempts to execute unauthorized commands or scripts via the web interface.
  • Review all existing administrator accounts within the GMS console for unauthorized additions or changes to privilege levels.

Immediate actions

Restrict GMS management interface to internal-only access.

IT Operations 24h

Mitigations

Patch SonicWall GMS as soon as the vendor releases security updates.

immediate IT Operations

Multiple vulnerabilities in GMS