6.6
CVE-2025-40602
- EPSS 0.28%
- Veröffentlicht 18.12.2025 10:58:41
- Zuletzt bearbeitet 19.12.2025 13:57:43
- Quelle PSIRT@sonicwall.com
- CVE-Watchlists
- Unerledigt
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sonicwall ≫ Sma6200 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma6200 Firmware Version >= 12.5.0 < 12.5.0-02283
Sonicwall ≫ Sma6210 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma6210 Firmware Version >= 12.5.0 < 12.5.0-02283
Sonicwall ≫ Sma7200 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma7200 Firmware Version >= 12.5.0 < 12.5.0-02283
Sonicwall ≫ Sma7210 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma7210 Firmware Version >= 12.5.0 < 12.5.0-02283
17.12.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog
SonicWall SMA1000 Missing Authorization Vulnerability
SchwachstelleSonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.
BeschreibungApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.51 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.