Impact
The vulnerability allows a local attacker to trigger an out-of-bounds read in the SWIPsec.sys driver of SonicWall Global VPN Client, which can result in a system crash. This flaw provides a denial‑of‑service condition but does not expose data or allow code execution.
Affected Systems
SonicWall Global VPN Client versions 4.10.8.1108 and all earlier releases are affected.
Risk and Exploitability
The flaw is limited to users who can run code locally on the affected machine. No EPSS score is reported and the vulnerability is not listed in CISA KEV. In the absence of a public exploit and with the requirement for local access, the overall risk is moderate, but the impact of a crash can be significant in production environments.
OpenCVE Enrichment