CVE-2025-40889

8.1

Nozomi Networks · Guardian and CMC

A path traversal vulnerability in the Time Machine functionality of Nozomi Networks products allows authenticated users to modify or disrupt files within the system data directory.

Executive summary

A path traversal vulnerability in Nozomi Networks Guardian and CMC allows authenticated users with limited privileges to compromise system file integrity and availability.

Vulnerability

This is a path traversal vulnerability (CWE-22) caused by missing input validation in the Time Machine feature, which can be exploited by an authenticated user with limited privileges to manipulate files within the /data directory.

Business impact

Successful exploitation allows an attacker to alter the structure and content of critical system files or impact their availability, which could lead to service disruption or unauthorized configuration changes. With a CVSS score of 8.1, this vulnerability represents a high risk to operational technology environments where these products are deployed to maintain system oversight and security.

Remediation

Immediate Action: Upgrade both Nozomi Networks Guardian and CMC installations to version 25.2.0 or later as specified in the vendor security advisory.

Proactive Monitoring: Review system access logs for anomalous requests directed at the Time Machine functionality and monitor for unexpected changes to file structures within the /data directory.

Compensating Controls: Ensure that access to the management interface is restricted to authorized personnel only and utilize network segmentation to limit the exposure of Guardian and CMC appliances.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available.

Analyst recommendation

Given the high CVSS severity and the potential for direct impact on system data integrity, organizations should prioritize patching their Nozomi Networks infrastructure. The ability for a limited-privilege user to affect system files underscores the necessity of applying the 25.2.0 update immediately to remediate the underlying input validation failure.

More Nozomi Networks CVEs

Sources

Originally found and disclosed by This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation., per the CVE Program record.