4.5
CVE-2025-40603
- EPSS 0.05%
- Veröffentlicht 31.10.2025 11:01:35
- Zuletzt bearbeitet 06.11.2025 16:26:50
- Quelle PSIRT@sonicwall.com
- CVE-Watchlists
- Unerledigt
A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sonicwall ≫ Sma 210 Firmware Version < 10.2.2.3
Sonicwall ≫ Sma 410 Firmware Version < 10.2.2.3
Sonicwall ≫ Sma 500v Firmware Version < 10.2.2.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.155 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 4.5 | 0.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.