Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service disruption.
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0013 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
11 Aug 2025, 14:59
Type | Values Removed | Values Added |
---|---|---|
First Time |
Sonicwall tz570w
Sonicwall tz370 Sonicwall tz570 Sonicwall nssp 11700 Sonicwall nsa 6700 Sonicwall nsv470 Sonicwall tz270w Sonicwall nsv870 Sonicwall tz470 Sonicwall nssp 10700 Sonicwall tz370w Sonicwall Sonicwall nsa 2700 Sonicwall nsv270 Sonicwall nsa 4700 Sonicwall nsa 3700 Sonicwall sonicos Sonicwall tz670 Sonicwall tz570p Sonicwall nssp 15700 Sonicwall tz270 Sonicwall nssp 13700 Sonicwall nsa 5700 Sonicwall tz470w |
|
References | () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0013 - Vendor Advisory | |
CPE | cpe:2.3:h:sonicwall:tz570w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv870:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_2700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_5700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv470:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_10700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsv270:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz470w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_11700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_6700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz670:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz570p:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz470:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz370w:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz270w:-:*:*:*:*:*:*:* cpe:2.3:o:sonicwall:sonicos:*:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz270:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_4700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nsa_3700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz370:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_15700:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:tz570:-:*:*:*:*:*:*:* cpe:2.3:h:sonicwall:nssp_13700:-:*:*:*:*:*:*:* |
30 Jul 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
Summary |
|
29 Jul 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-29 22:15
Updated : 2025-08-11 14:59
NVD link : CVE-2025-40600
Mitre link : CVE-2025-40600
CVE.ORG link : CVE-2025-40600
JSON object : View
Products Affected
sonicwall
- tz670
- sonicos
- nssp_13700
- nsa_4700
- tz370w
- nssp_11700
- tz370
- nsv870
- tz570
- nssp_15700
- nsa_2700
- tz270w
- nsv470
- nssp_10700
- tz570p
- nsa_6700
- tz570w
- tz270
- nsv270
- nsa_3700
- tz470
- tz470w
- nsa_5700
CWE
CWE-134
Use of Externally-Controlled Format String