PT-2025-31264 · Sonicwall · Sonicos

Published

2025-07-29

·

Updated

2025-08-14

·

CVE-2025-40600

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SonicWall versions prior to 7.3.0-7012
Description A format string vulnerability exists in the SonicOS SSL VPN interface, allowing a remote, unauthenticated attacker to cause a denial-of-service (DoS) condition. The vulnerability is due to the improper handling of externally-controlled format strings.
Recommendations SonicWall versions prior to 7.3.0-7012 should be upgraded to version 7.3.0-7012 or later.

Fix

DoS

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

BDU:2025-14516
CVE-2025-40600

Affected Products

Sonicos