216.73.216.133

CVE-2025-40605

· Published 20/11/2025 15:17 · Modified 12/12/2025 15:43

Labels: CVE-2025-40605 2025-11-20CVE-2025-40605CWE-23[email protected]

Essential information

Published
20/11/2025 15:17
Modified
12/12/2025 15:43
Author
Creator
CVSS
5.3 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS metrics

Description

A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sonicwall / email security appliance 5000 firmware cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:*
sonicwall / email security appliance 5000 cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:*
sonicwall / email security appliance 5050 firmware cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:*
sonicwall / email security appliance 5050 cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:*
sonicwall / email security appliance 7000 firmware cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:*
sonicwall / email security appliance 7000 cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:*
sonicwall / email security appliance 7050 firmware cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:*
sonicwall / email security appliance 7050 cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:*
sonicwall / email security appliance 9000 firmware cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:*
sonicwall / email security appliance 9000 cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:*

References