CVE-2025-40604: Critical severity SonicWall Email Security Appliance 5000 Firmware vulnerability
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40604?
CVE-2025-40604 is considered a critical vulnerability due to the potential for persistent arbitrary code execution.
How do I fix CVE-2025-40604?
To fix CVE-2025-40604, it is recommended to update the SonicWall Email Security appliance to a firmware version that addresses this vulnerability.
What systems are affected by CVE-2025-40604?
CVE-2025-40604 affects SonicWall Email Security appliances running firmware versions up to and including 10.0.33.8195.
What is the impact of CVE-2025-40604?
The impact of CVE-2025-40604 allows attackers with VMDK or datastore access to modify system files and execute arbitrary code.
Is there a workaround for CVE-2025-40604?
Currently, there are no definitive workarounds for CVE-2025-40604 apart from applying the relevant patches or firmware updates.