CVE-2025-40602
KEVMEDIUM 6.6EPSS 2.1%
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
- CVSS v3.1
- 6.6 MEDIUM
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H - EPSS
- 2.11% chance of exploitation in the next 30 days, 81th percentile
- CISA KEV
- added 2025-12-17
- Published
- 2025-12-18