CVE-2025-40604

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
Configurations

No configuration.

History

20 Nov 2025, 19:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

20 Nov 2025, 15:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-20 15:17

Updated : 2025-11-21 15:13


NVD link : CVE-2025-40604

Mitre link : CVE-2025-40604

CVE.ORG link : CVE-2025-40604


JSON object : View

Products Affected

No product.

CWE
CWE-494

Download of Code Without Integrity Check