Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
References
Configurations
No configuration.
History
20 Nov 2025, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
20 Nov 2025, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-20 15:17
Updated : 2025-11-21 15:13
NVD link : CVE-2025-40604
Mitre link : CVE-2025-40604
CVE.ORG link : CVE-2025-40604
JSON object : View
Products Affected
No product.
CWE
CWE-494
Download of Code Without Integrity Check
