CVE-2025-3719

8.1

Nozomi Networks · Guardian and CMC

An authorization flaw in the CLI allows authenticated users with limited privileges to execute administrative commands, potentially leading to unauthorized configuration changes or service disruption.

Executive summary

A critical access control vulnerability in Nozomi Networks Guardian and CMC allows low-privileged users to execute administrative CLI commands, posing a significant risk to device integrity.

Vulnerability

This is an incorrect authorization vulnerability (CWE-863) within the CLI functionality. An authenticated user with limited privileges can bypass intended restrictions to perform administrative actions, including altering device configurations or impacting system availability.

Business impact

The ability for a low-privileged user to modify device configurations or impact availability presents a substantial risk to operational technology environments. Given the CVSS score of 8.1, this vulnerability is classified as High severity, as it could lead to unauthorized system control, potential downtime, or the manipulation of security-critical infrastructure.

Remediation

Immediate Action: Upgrade both Nozomi Networks Guardian and CMC instances to version 25.2.0 or later to remediate the authorization flaw.

Proactive Monitoring: Monitor CLI access logs for anomalous command execution patterns or unauthorized attempts by low-privileged accounts to access restricted administrative functions.

Compensating Controls: Restrict administrative CLI access to trusted management workstations and enforce the principle of least privilege for all user accounts until patches can be applied.

Exploitation status

Public Exploit Available: No — exploit_available (unknown).

Analyst recommendation

Due to the potential for unauthorized administrative control over industrial security appliances, this vulnerability must be treated with high urgency. Administrators should prioritize the deployment of the 25.2.0 update across all affected Guardian and CMC deployments to ensure that authorization controls are correctly enforced and to prevent potential configuration tampering.

More Nozomi Networks CVEs

Sources

Originally found and disclosed by This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation., per the CVE Program record.