Description
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
Published: 2026-08-07
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a local attacker to trigger an out-of-bounds read in the SWIPsec.sys driver of SonicWall Global VPN Client, which can result in a system crash. This flaw provides a denial‑of‑service condition but does not expose data or allow code execution.

Affected Systems

SonicWall Global VPN Client versions 4.10.8.1108 and all earlier releases are affected.

Risk and Exploitability

The flaw is limited to users who can run code locally on the affected machine. The CVSS score is 5.5, the EPSS score indicates <1%, and the vulnerability is not listed in CISA KEV. In the absence of a public exploit and with the requirement for local access, the overall risk is moderate, but the impact of a crash can be significant in production environments.

Generated by OpenCVE AI on August 13, 2026 at 10:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SonicWall Global VPN Client to the latest version that contains the SWIPsec.sys fix
  • If an update is not immediately available, minimize exposure by uninstalling or disabling Global VPN Client until a patch is released
  • Monitor SonicWall security advisories for updates or temporary mitigations
  • When upgrading, confirm that the new SWIPsec.sys is in place and the client service is restarted

Generated by OpenCVE AI on August 13, 2026 at 10:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in SonicWall Global VPN Client SWIPsec.sys Leads to System Crash

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall global Vpn Client
Vendors & Products Sonicwall
Sonicwall global Vpn Client

Fri, 07 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
Weaknesses CWE-125
References

Subscriptions

Sonicwall Global Vpn Client
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-11T19:29:41.797Z

Reserved: 2026-07-24T08:34:11.798Z

Link: CVE-2026-66151

cve-icon Vulnrichment

Updated: 2026-08-11T19:29:38.671Z

cve-icon NVD

Status : Received

Published: 2026-08-07T20:16:52.750

Modified: 2026-08-11T20:18:37.943

Link: CVE-2026-66151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses