CVE-2025-40605
Severity CVSS v4.0:
Pending analysis
Type:
CWE-23
Relative Path Traversal
Publication date:
20/11/2025
Last modified:
12/12/2025
Description
A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:sonicwall:email_security_appliance_5000_firmware:*:*:*:*:*:*:*:* | 10.0.33.8195 (including) | |
| cpe:2.3:h:sonicwall:email_security_appliance_5000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:email_security_appliance_5050_firmware:*:*:*:*:*:*:*:* | 10.0.33.8195 (including) | |
| cpe:2.3:h:sonicwall:email_security_appliance_5050:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:email_security_appliance_7000_firmware:*:*:*:*:*:*:*:* | 10.0.33.8195 (including) | |
| cpe:2.3:h:sonicwall:email_security_appliance_7000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:email_security_appliance_7050_firmware:*:*:*:*:*:*:*:* | 10.0.33.8195 (including) | |
| cpe:2.3:h:sonicwall:email_security_appliance_7050:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:sonicwall:email_security_appliance_9000_firmware:*:*:*:*:*:*:*:* | 10.0.33.8195 (including) | |
| cpe:2.3:h:sonicwall:email_security_appliance_9000:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



