CVE-2025-20033

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Jan 9, 2025
CWE ID 1287

Summary

CVE-2024-40765 is an integer-based buffer overflow vulnerability affecting SonicOS through its IPSec implementation. Under specific conditions, a remote attacker can exploit this flaw by sending a maliciously crafted IKEv2 payload, causing a Denial of Service (DoS) or potentially executing arbitrary code. This vulnerability poses a significant risk to network availability and security. Users are advised to apply patches or updates as soon as they become available to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mattermost Server

Affected Vendors

  • Mattermost, Inc.