Path Traversal Vulnerability in Time Machine Functionality by Nozomi Networks
CVE-2025-40889
7.2HIGH
What is CVE-2025-40889?
A path traversal vulnerability has been identified within the Time Machine functionality of Nozomi Networks' product. This flaw results from inadequate validation of two input parameters, allowing authenticated users with limited privileges to issue crafted requests. As a consequence, attackers could manipulate the structure and content of files within the /data directory, potentially compromising the availability and integrity of those files.
Affected Version(s)
CMC 0 < 25.2.0
Guardian 0 < 25.2.0
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation.