MEDIUM

CVE-2025-40602

Sonicwall Sma6200 Firmware 2025-12-18 CVSS v3.1
CVSS
6.6
KEV

Description

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

Summary dbcve.org

A local privilege escalation vulnerability exists in the SonicWall SMA1000 appliance management console (AMC) due to insufficient authorization controls, allowing a local authenticated attacker to gain elevated privileges beyond their assigned role level.

Mitigation

Apply vendor-supplied patches or updates for the SMA1000 series that address authorization validation in the AMC component.

Weakness (CWE)

CWE-250
CWE-862 Missing Authorization

EPSS Score

2.08%
Probability of exploitation in next 30 days
80.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE