Attackers sharply increased exploitation attempts against SonicWall Global Management System (GMS) in October, targeting the SQL injection flaw CVE-2023-34133 to bypass authentication and extract sensitive data from SGMS databases. Mitsui Bussan Secure Directions reported that its SOC had seen intermittent activity since the vulnerability was disclosed, but detections rose notably as public proof-of-concept exploit code circulated. The observed attacks primarily originated from the United States, with additional traffic from France and Germany.
The vulnerability affects SonicWall GMS 9.3.2-SP1 and earlier and SonicWall Analytics 2.5.0.4-R7 and earlier, according to SonicWall's advisory SNWLID-2023-0010. MBSD said the exploit traffic included HTTP GET requests using UNION SELECT payloads designed to enumerate domain IDs and retrieve active user credentials from the SGMS database, creating a risk of administrative compromise and data theft. Organizations running exposed instances were urged to update to the latest fixed versions immediately.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC reported a notable rise in detections during October 2024 involving exploitation attempts against SonicWall GMS via CVE-2023-34133. The observed activity included SQL injection requests aimed at extracting domain IDs and active user credentials from the SGMS database.
The SonicWall GMS SQL injection vulnerability CVE-2023-34133 was publicly disclosed in July 2023. The flaw can enable remote authentication bypass and theft of sensitive information.
MITRE published the CVE record for CVE-2023-34133, covering an SQL injection vulnerability affecting SonicWall Global Management System.
After the July 2023 disclosure, MBSD-SOC observed intermittent attacks targeting CVE-2023-34133. The article also notes that proof-of-concept exploit code had become publicly available.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.