
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
An improper privilege management vulnerability was identified in the SonicWall NetExtender Windows (32 and 64 bit) client, tracked as CVE-2025-23008. The vulnerability was disclosed on April 10, 2025, affecting NetExtender Windows versions 10.3.1 and earlier. This security issue allows low-privileged attackers to modify configurations in the affected systems (NVD, ASEC).
The vulnerability has been classified under CWE-250 (Execution with Unnecessary Privileges). According to the CVSS 3.1 scoring system, it received a base score of 7.2 (HIGH) with the following vector: CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H, indicating physical access is required, low attack complexity, low privileges required, user interaction required, and high impact on confidentiality, integrity, and availability (NVD).
The vulnerability's exploitation could lead to unauthorized configuration modifications in the SonicWall NetExtender Windows client. With a high CVSS score affecting confidentiality, integrity, and availability, this vulnerability poses significant risks to system security and stability (ASEC).
SonicWall has released security updates to address this vulnerability. Users are strongly advised to upgrade to NetExtender Windows version 10.3.2 or higher, which contains the necessary security patches to resolve the issue (ASEC).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”