CVE-2025-40603
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-31
Last updated on: 2025-11-06
Assigner: SonicWALL, Inc.
Description
Description
A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sonicwall | sma_210_firmware | to 10.2.2.3 (exc) |
| sonicwall | sma_210 | * |
| sonicwall | sma_410_firmware | to 10.2.2.3 (exc) |
| sonicwall | sma_410 | * |
| sonicwall | sma_500v_firmware | to 10.2.2.3 (exc) |
| sonicwall | sma_500v | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-532 | The product writes sensitive information to a log file. |