Improper Privilege Management in SonicWall NetExtender Client
CVE-2025-23008

7.2HIGH

Key Information:

Vendor
Sonicwall
Vendor
CVE Published:
10 April 2025

Summary

An improper privilege management vulnerability exists in the SonicWall NetExtender Windows client that enables a low privileged attacker to alter configuration settings. This issue can potentially allow unauthorized modifications, leading to further security risks within the affected systems.

Affected Version(s)

NetExtender Windows 10.3.1 and earlier versions

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.