{"id":"CVE-2025-40603","title":"A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.","summary":"A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.","severity":"medium","cvss":4.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-532"],"vendor":"sonicwall","product":"sma_210_firmware","affected":["sma_210_firmware < 10.2.2.3","sma_410_firmware < 10.2.2.3","sma_500v_firmware < 10.2.2.3"],"patched":["sma_210_firmware 10.2.2.3","sma_410_firmware 10.2.2.3","sma_500v_firmware 10.2.2.3"],"published":"2025-10-31","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-40603","references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0017","label":"PSIRT@sonicwall.com"}],"tags":["nvd"],"epss":0.0048,"epssPercentile":0.39412,"ingestedAt":"2026-10-07T21:54:14.918Z","slug":"CVE-2025-40603","body":"## Overview\n\nA potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, authenticated administrator, under certain conditions to view partial users credential data.\n\n## Affected\n\n- `sma_210_firmware < 10.2.2.3`\n- `sma_410_firmware < 10.2.2.3`\n- `sma_500v_firmware < 10.2.2.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `sma_210_firmware 10.2.2.3`\n- `sma_410_firmware 10.2.2.3`\n- `sma_500v_firmware 10.2.2.3`","depth":"sunlit","depthScore":25,"depthScoreParts":{"impact":24.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}