CVE-2025-40604 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allo…
Critical CVSS: 9.8

CVE-2025-40604

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
Vendor
Sonicwall
Product
Email Security Appliance 5000 Firmware
CWE
CWE-494
Yayın Tarihi
2025-11-20 15:17:28
Güncelleme
2025-12-12 15:44:04
Source Identifier
PSIRT@sonicwall.com
KEV Date Added
-

Kategoriler

Referanslar