Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Dec 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sonicwall email Security Appliance 5000
Sonicwall email Security Appliance 5000 Firmware Sonicwall email Security Appliance 5050 Sonicwall email Security Appliance 5050 Firmware Sonicwall email Security Appliance 7000 Sonicwall email Security Appliance 7000 Firmware Sonicwall email Security Appliance 7050 Sonicwall email Security Appliance 7050 Firmware Sonicwall email Security Appliance 9000 Sonicwall email Security Appliance 9000 Firmware |
|
| CPEs | cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sonicwall email Security Appliance 5000
Sonicwall email Security Appliance 5000 Firmware Sonicwall email Security Appliance 5050 Sonicwall email Security Appliance 5050 Firmware Sonicwall email Security Appliance 7000 Sonicwall email Security Appliance 7000 Firmware Sonicwall email Security Appliance 7050 Sonicwall email Security Appliance 7050 Firmware Sonicwall email Security Appliance 9000 Sonicwall email Security Appliance 9000 Firmware |
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sonicwall
Sonicwall email Security |
|
| Vendors & Products |
Sonicwall
Sonicwall email Security |
Thu, 20 Nov 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 20 Nov 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution. | |
| Weaknesses | CWE-494 | |
| References |
|
Status: PUBLISHED
Assigner: sonicwall
Published: 2025-11-20T12:17:14.138Z
Updated: 2025-11-21T05:02:06.383Z
Reserved: 2025-04-16T08:34:51.361Z
Link: CVE-2025-40604
Updated: 2025-11-20T18:28:54.889Z
Status : Analyzed
Published: 2025-11-20T15:17:28.750
Modified: 2025-12-12T15:44:04.973
Link: CVE-2025-40604
No data.