MEDIUM
CVE-2025-40602
CVSS
6.6
KEV
Description
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
Summary dbcve.org
A local privilege escalation vulnerability exists in the SonicWall SMA1000 appliance management console (AMC) due to insufficient authorization controls, allowing a local authenticated attacker to gain elevated privileges beyond their assigned role level.
Mitigation
Apply vendor-supplied patches or updates for the SMA1000 series that address authorization validation in the AMC component.
Weakness (CWE)
CWE-250
CWE-862
Missing Authorization
EPSS Score
2.08%
Probability of exploitation in next 30 days
80.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.