PT-2025-31264 · Sonicwall · Sonicos

Published

2025-07-29

·

Updated

2025-07-31

·

CVE-2025-40600

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

SonicWall versions prior to 7.3.0-7012

**Description:**

A format string vulnerability exists in the SonicOS SSL VPN interface, allowing a remote, unauthenticated attacker to cause a denial-of-service (DoS) condition. The vulnerability is due to the improper handling of externally-controlled format strings.

**Recommendations:**

SonicWall versions prior to 7.3.0-7012 should be upgraded to version 7.3.0-7012 or later.

Fix

DoS

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

CVE-2025-40600

Affected Products

Sonicos