CVE 7.2 HIGH

Incorrect authorization for CLI in Guardian/CMC before 25.2.0_CVE-2025-3719

7.2 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Description

An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can issue administrative CLI commands, altering the device configuration, and/or affecting its availability.

Basic Information

ID CVE-2025-3719
Source Nozomi
Published Oct 7, 2025 at 12:34
Modified Oct 7, 2025 at 13:19

Affected Product

Vendor Nozomi Networks
Product Guardian
Affected Versions Nozomi Networks Guardian 0
Nozomi Networks CMC 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.