CVE-2025-40898

8.1

Nozomi Networks · Guardian and CMC

A path traversal vulnerability exists in the Import Arc data archive functionality of Nozomi Networks Guardian and CMC, allowing authenticated users to write arbitrary files.

Executive summary

A path traversal vulnerability in Nozomi Networks Guardian and CMC allows authenticated users to perform arbitrary file writes, potentially compromising device configuration and system availability.

Vulnerability

The vulnerability is a path traversal flaw (CWE-22) residing in the Import Arc data archive component. It requires an authenticated user with limited privileges to upload a crafted archive to execute the attack.

Business impact

The ability to write arbitrary files to the system presents a high risk to operational integrity. By modifying device configurations or interfering with core system files, an attacker could disrupt critical monitoring services, leading to significant system downtime and loss of visibility into industrial networks. The CVSS score of 8.1 reflects the high potential for impact on system integrity and availability.

Remediation

Immediate Action: Upgrade both Nozomi Networks Guardian and CMC instances to version 25.5.0 or later to apply the necessary input validation patches.

Proactive Monitoring: Review system access logs for unusual file upload activity or unauthorized modifications to configuration files.

Compensating Controls: Restrict access to the Import Arc data archive functionality to trusted administrative accounts only until the update can be deployed.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for total loss of system integrity and availability, organizations should prioritize updating their Nozomi Networks appliances to version 25.5.0. While the vulnerability requires authenticated access, the risk posed by compromised internal accounts makes immediate remediation essential to maintain the security of critical infrastructure environments.

More Nozomi Networks CVEs

Sources

Originally found and disclosed by This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation., per the CVE Program record.