CVE-2025-20033
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Jan 9, 2025
CWE ID 1287
Summary
CVE-2024-40765 is an integer-based buffer overflow vulnerability affecting SonicOS through its IPSec implementation. Under specific conditions, a remote attacker can exploit this flaw by sending a maliciously crafted IKEv2 payload, causing a Denial of Service (DoS) or potentially executing arbitrary code. This vulnerability poses a significant risk to network availability and security. Users are advised to apply patches or updates as soon as they become available to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.