CVE-2025-40604
Last modified
CVE-2025-40604 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Email Security Appliance 5000 Firmware | <= 10.0.33.8195 |
| Sonicwall | Email Security Appliance 5050 Firmware | <= 10.0.33.8195 |
| Sonicwall | Email Security Appliance 7000 Firmware | <= 10.0.33.8195 |
| Sonicwall | Email Security Appliance 7050 Firmware | <= 10.0.33.8195 |
| Sonicwall | Email Security Appliance 9000 Firmware | <= 10.0.33.8195 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-40604?
How severe is CVE-2025-40604?
How do I fix CVE-2025-40604?
Are you affected by CVE-2025-40604?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
