6.6
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Basic Information
ID
CVE-2025-40602
Source
sonicwall
Published
Dec 18, 2025 at 10:58
Modified
Dec 18, 2025 at 11:32
Affected Product
Vendor
SonicWall
Product
SMA1000
Version
12.4.3-03093 (platform-hotfix) and earlier versions
Affected Versions
SonicWall SMA1000 12.4.3-03093 (platform-hotfix) and earlier versions
SonicWall SMA1000 12.5.0-02002 (platform-hotfix) and earlier versions
SonicWall SMA1000 12.5.0-02002 (platform-hotfix) and earlier versions