6.6
CVE-2025-40602
- EPSS 0.15%
- Veröffentlicht 18.12.2025 10:58:41
- Zuletzt bearbeitet 19.12.2025 13:57:43
- Quelle PSIRT@sonicwall.com
- CVE-Watchlists
- Unerledigt
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sonicwall ≫ Sma6200 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma6200 Firmware Version >= 12.5.0 < 12.5.0-02283
Sonicwall ≫ Sma6210 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma6210 Firmware Version >= 12.5.0 < 12.5.0-02283
Sonicwall ≫ Sma7200 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma7200 Firmware Version >= 12.5.0 < 12.5.0-02283
Sonicwall ≫ Sma7210 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma7210 Firmware Version >= 12.5.0 < 12.5.0-02283
VulnDex Vulnerability Enrichment
17.12.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog
SonicWall SMA1000 Missing Authorization Vulnerability
SchwachstelleSonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.
BeschreibungApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.15% | 0.356 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.