Access Control Vulnerability in CLI Functionality of Network Management Product by Nozomi Networks
CVE-2025-3719

7.2HIGH

Key Information:

Vendor
CVE Published:
7 October 2025

What is CVE-2025-3719?

A significant access control vulnerability exists in the Command Line Interface (CLI) functionality of Nozomi Networks' product. This flaw arises from inadequate enforcement of access restrictions, allowing authenticated users with limited privileges to execute administrative commands. Consequently, these users can make unauthorized changes to device configurations, potentially leading to system instability and unauthorized access to sensitive functionalities.

Affected Version(s)

CMC 0 < 25.2.0

Guardian 0 < 25.2.0

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation.
.