Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-40604


Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.


Published

2025-11-20T15:17:28.750

Last Modified

2025-12-12T15:44:04.973

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-494

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System sonicwall email_security_appliance_5000_firmware ≤ 10.0.33.8195 Yes
Hardware sonicwall email_security_appliance_5000 - No
Operating System sonicwall email_security_appliance_5050_firmware ≤ 10.0.33.8195 Yes
Hardware sonicwall email_security_appliance_5050 - No
Operating System sonicwall email_security_appliance_7000_firmware ≤ 10.0.33.8195 Yes
Hardware sonicwall email_security_appliance_7000 - No
Operating System sonicwall email_security_appliance_7050_firmware ≤ 10.0.33.8195 Yes
Hardware sonicwall email_security_appliance_7050 - No
Operating System sonicwall email_security_appliance_9000_firmware ≤ 10.0.33.8195 Yes
Hardware sonicwall email_security_appliance_9000 - No

References