7.5
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Description
A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cause an impacted firewall to crash.
Basic Information
ID
CVE-2025-40601
Source
sonicwall
Published
Nov 20, 2025 at 12:26
Modified
Nov 20, 2025 at 18:31
Affected Product
Vendor
SonicWall
Product
SonicOS
Version
7.3.0-7012 and older versions
Affected Versions
SonicWall SonicOS 7.3.0-7012 and older versions
SonicWall SonicOS 8.0.2-8011 and older versions
SonicWall SonicOS 8.0.2-8011 and older versions