CVE-2025-40604
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.0.33.8195 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Email Security Appliance 5000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.0.33.8195 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Email Security Appliance 5050 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.0.33.8195 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Email Security Appliance 7000 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.0.33.8195 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Email Security Appliance 7050 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.0.33.8195 |
| Running on/with | Platform Versions |
|---|---|
Sonicwall Email Security Appliance 9000 | All versions |
References (1)
Source: PSIRT@sonicwall.com
Vendor Advisory
Timeline
No history available yet.