Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-40600


Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.


Published

2025-07-29T22:15:24.927

Last Modified

2025-08-11T14:59:40.867

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-134

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System sonicwall sonicos < 7.3.0-7012 Yes
Hardware sonicwall nsa_2700 - No
Hardware sonicwall nsa_3700 - No
Hardware sonicwall nsa_4700 - No
Hardware sonicwall nsa_5700 - No
Hardware sonicwall nsa_6700 - No
Hardware sonicwall nssp_10700 - No
Hardware sonicwall nssp_11700 - No
Hardware sonicwall nssp_13700 - No
Hardware sonicwall nssp_15700 - No
Hardware sonicwall nsv270 - No
Hardware sonicwall nsv470 - No
Hardware sonicwall nsv870 - No
Hardware sonicwall tz270 - No
Hardware sonicwall tz270w - No
Hardware sonicwall tz370 - No
Hardware sonicwall tz370w - No
Hardware sonicwall tz470 - No
Hardware sonicwall tz470w - No
Hardware sonicwall tz570 - No
Hardware sonicwall tz570p - No
Hardware sonicwall tz570w - No
Hardware sonicwall tz670 - No

References