6.6
CVE-2025-40602
- EPSS 2.11%
- Veröffentlicht 18.12.2025 10:58:41
- Zuletzt bearbeitet 19.12.2025 13:57:43
- Erkennungen
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sonicwall ≫ Sma6200 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma6200 Firmware Version >= 12.5.0 < 12.5.0-02283
Sonicwall ≫ Sma6210 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma6210 Firmware Version >= 12.5.0 < 12.5.0-02283
Sonicwall ≫ Sma7200 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma7200 Firmware Version >= 12.5.0 < 12.5.0-02283
Sonicwall ≫ Sma7210 Firmware Version < 12.4.3-03245
Sonicwall ≫ Sma7210 Firmware Version >= 12.5.0 < 12.5.0-02283
VulnDex Vulnerability Enrichment
17.12.2025: CISA Known Exploited Vulnerabilities (KEV) Catalog
SonicWall SMA1000 Missing Authorization Vulnerability
SchwachstelleSonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.
BeschreibungApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.11% | 0.802 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 6.6 | 0.7 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
|
CWE-250 Execution with Unnecessary Privileges
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0019
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-40602