CVE-2025-40603

A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*

History

06 Nov 2025, 16:26

Type Values Removed Values Added
First Time Sonicwall sma 500v
Sonicwall sma 210 Firmware
Sonicwall
Sonicwall sma 210
Sonicwall sma 410 Firmware
Sonicwall sma 410
Sonicwall sma 500v Firmware
References () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0017 - () https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0017 - Vendor Advisory
CPE cpe:2.3:o:sonicwall:sma_210_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_210:-:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_500v:-:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_410_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sonicwall:sma_500v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sonicwall:sma_410:-:*:*:*:*:*:*:*

31 Oct 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.5

31 Oct 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-31 11:15

Updated : 2025-11-06 16:26


NVD link : CVE-2025-40603

Mitre link : CVE-2025-40603

CVE.ORG link : CVE-2025-40603


JSON object : View

Products Affected

sonicwall

  • sma_500v_firmware
  • sma_210
  • sma_210_firmware
  • sma_410
  • sma_410_firmware
  • sma_500v
CWE
CWE-532

Insertion of Sensitive Information into Log File