SonicWall SonicOS Post-authentication Absolute Path Traversal Vulnerability Allowing Arbitrary File Read

Vulnerability

A post-authentication absolute path traversal vulnerability has been identified in SonicWall SonicOS management. This vulnerability allows remote attackers to read arbitrary files on the system. It affects multiple generations of SonicWall firewalls and certain versions of the SonicWall NSv product.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the affected system.

Remediation

Users are advised to upgrade to SonicWall SonicOS versions 6.5.5.1-6n and higher, 7.0.1-5165 and higher, 7.1.3-7015 and higher, or 8.0.0-8037 and higher, depending on their specific firewall model.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.