CVE Vulnerabilities

CVE-2025-40600

Use of Externally-Controlled Format String

Published: Jul 29, 2025 | Modified: Aug 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

NameVendorStart VersionEnd Version
SonicosSonicwall7.1.1-7040 (including)7.3.0-7012 (excluding)

Potential Mitigations

References