---
id: CVE-2026-66151
title: >-
  SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to
  an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could
  allow a local attacker to cause a system crash.
summary: >-
  SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to
  an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could
  allow a local attacker to cause a system crash.
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
published: '2026-08-07'
updated: '2026-08-28'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-66151'
references:
  - url: 'https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0010'
    label: PSIRT@sonicwall.com
tags:
  - nvd
epss: 0.0011
epssPercentile: 0.01452
ingestedAt: '2026-08-29T16:39:14.392Z'
---

## Overview

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
