← לוח פגיעויות

CVE-2025-40602

בינונית 6.6 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
SonicWall SMA1000 Missing Authorization Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable

תיאור (מקור, אנגלית)

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

מדדים

CVSS 3.1
6.6 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
2% (אחוזון 100) נכון ל-26/7/2026
CWE
CWE-250, CWE-862

מוצרים מושפעים

sonicwall: sma6200 firmware; sonicwall: sma6200; sonicwall: sma6210 firmware; sonicwall: sma6210; sonicwall: sma7200 firmware; sonicwall: sma7200; sonicwall: sma7210 firmware; sonicwall: sma7210; sonicwall: sma8200v

קישורים