Vulnerability Description
A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sonicwall | Sma 500V Firmware | < 10.2.2.1-90sv |
| Sonicwall | Sma 500V | - |
| Sonicwall | Sma 210 Firmware | < 10.2.2.1-90sv |
| Sonicwall | Sma 210 | - |
| Sonicwall | Sma 410 Firmware | < 10.2.2.1-90sv |
| Sonicwall | Sma 410 | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-40597?
CVE-2025-40597 is a vulnerability with a CVSS score of 7.5 (HIGH). A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS) or potentially results in code execution.
How severe is CVE-2025-40597?
CVE-2025-40597 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-40597?
Check the references section above for vendor advisories and patch information. Affected products include: Sonicwall Sma 500V Firmware, Sonicwall Sma 500V, Sonicwall Sma 210 Firmware, Sonicwall Sma 210, Sonicwall Sma 410 Firmware.