V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-40604
CVE
Critical

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verif…

CVSS
9.8
Critical
EPSS
0.00
p6
Published
2025-01-01
Updated
2025-01-01
Description

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.

Tags · CWE
Pre-auth
CWE-494
CAPEC-184
CAPEC-185
CAPEC-186
CAPEC-187
CAPEC-533
CAPEC-538
CAPEC-657
CAPEC-662
CAPEC-691
CAPEC-692
CAPEC-693
CAPEC-695
Affected products
Email_security_appliance_5000_firmwareEmail_security_appliance_5050_firmwareEmail_security_appliance_7000_firmwareEmail_security_appliance_7050_firmwareEmail_security_appliance_9000_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.002 · p6
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-187 · CWE-494
└ via CAPEC-662 · CWE-494
└ via CAPEC-186 · CWE-494
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
email_security_appliance_5000_firmware*Tracked
email_security_appliance_5050_firmware*Tracked
email_security_appliance_7000_firmware*Tracked
email_security_appliance_7050_firmware*Tracked
email_security_appliance_9000_firmware*Tracked
Source databases
CVE
Related vulnerabilities