Description
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
Published: 2026-08-07
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a local attacker to trigger an out-of-bounds read in the SWIPsec.sys driver of SonicWall Global VPN Client, which can result in a system crash. This flaw provides a denial‑of‑service condition but does not expose data or allow code execution.

Affected Systems

SonicWall Global VPN Client versions 4.10.8.1108 and all earlier releases are affected.

Risk and Exploitability

The flaw is limited to users who can run code locally on the affected machine. No EPSS score is reported and the vulnerability is not listed in CISA KEV. In the absence of a public exploit and with the requirement for local access, the overall risk is moderate, but the impact of a crash can be significant in production environments.

Generated by OpenCVE AI on August 7, 2026 at 21:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SonicWall Global VPN Client to the latest version that contains the SWIPsec.sys fix
  • If an update is not immediately available, minimize exposure by uninstalling or disabling Global VPN Client until a patch is released
  • Monitor SonicWall security advisories for updates or temporary mitigations
  • When upgrading, confirm that the new SWIPsec.sys is in place and the client service is restarted

Generated by OpenCVE AI on August 7, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Sonicwall
Sonicwall global Vpn Client
Vendors & Products Sonicwall
Sonicwall global Vpn Client

Fri, 07 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
Weaknesses CWE-125
References

Subscriptions

Sonicwall Global Vpn Client
cve-icon MITRE

Status: PUBLISHED

Assigner: sonicwall

Published:

Updated: 2026-08-07T20:10:19.486Z

Reserved: 2026-07-24T08:34:11.798Z

Link: CVE-2026-66151

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T21:30:18Z

Weaknesses