9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.
Basic Information
ID
CVE-2025-40600
Source
sonicwall
Published
Jul 29, 2025 at 21:11
Modified
Jul 30, 2025 at 15:07
Affected Product
Vendor
SonicWall
Product
SonicOS
Version
7.2.0-7015 and older versions
Affected Versions
SonicWall SonicOS 7.2.0-7015 and older versions