Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sonicwall
Sonicwall email Security |
|
| Vendors & Products |
Sonicwall
Sonicwall email Security |
Thu, 20 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 20 Nov 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution. | |
| Weaknesses | CWE-494 | |
| References |
|
Status: PUBLISHED
Assigner: sonicwall
Published: 2025-11-20T12:17:14.138Z
Updated: 2025-11-21T05:02:06.383Z
Reserved: 2025-04-16T08:34:51.361Z
Link: CVE-2025-40604
Updated: 2025-11-20T18:28:54.889Z
Status : Awaiting Analysis
Published: 2025-11-20T15:17:28.750
Modified: 2025-11-21T15:13:59.083
Link: CVE-2025-40604
No data.