A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.
History

Fri, 12 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall email Security Appliance 5000
Sonicwall email Security Appliance 5000 Firmware
Sonicwall email Security Appliance 5050
Sonicwall email Security Appliance 5050 Firmware
Sonicwall email Security Appliance 7000
Sonicwall email Security Appliance 7000 Firmware
Sonicwall email Security Appliance 7050
Sonicwall email Security Appliance 7050 Firmware
Sonicwall email Security Appliance 9000
Sonicwall email Security Appliance 9000 Firmware
CPEs cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:*
Vendors & Products Sonicwall email Security Appliance 5000
Sonicwall email Security Appliance 5000 Firmware
Sonicwall email Security Appliance 5050
Sonicwall email Security Appliance 5050 Firmware
Sonicwall email Security Appliance 7000
Sonicwall email Security Appliance 7000 Firmware
Sonicwall email Security Appliance 7050
Sonicwall email Security Appliance 7050 Firmware
Sonicwall email Security Appliance 9000
Sonicwall email Security Appliance 9000 Firmware

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall email Security
Vendors & Products Sonicwall
Sonicwall email Security

Thu, 20 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Nov 2025 12:30:00 +0000

Type Values Removed Values Added
Description A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.
Weaknesses CWE-23
References

cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published: 2025-11-20T12:19:17.871Z

Updated: 2025-11-20T18:30:31.164Z

Reserved: 2025-04-16T08:34:59.662Z

Link: CVE-2025-40605

cve-icon Vulnrichment

Updated: 2025-11-20T18:30:16.655Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-20T15:17:28.917

Modified: 2025-12-12T15:43:42.043

Link: CVE-2025-40605

cve-icon Redhat

No data.