NN-2025:3-01

Incorrect authorization for traces request/download in CMC before 25.1.0

Last update: 2025-08-26

Advisory IDNN-2025:3-01
TopicIncorrect authorization for traces request/download in CMC before 25.1.0
CWE ImpactCWE-863: Incorrect Authorization
Issue date2025-08-26
AffectsCMC < v25.1.0
CVE Name(s)CVE-2025-1501
CVSS DetailsCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score5.3 (CVSS v4.0)
4.3 (CVSS v3.1)
CVE Risk LevelMedium (CVSS v4.0)
Medium (CVSS v3.1)
Risk Level for Nozomi customersMedium

Summary

An access control vulnerability was discovered in the Request Trace and Download Trace functionalities due to a specific access restriction not being properly enforced for users with limited privileges.

Impact

An authenticated user with limited privileges can request and download trace files due to improper access restrictions, potentially exposing unauthorized network data.

Affected Products

CMC < v25.1.0

Workarounds and Mitigations

Use internal firewall features to limit access to the web management interface.

Solutions

Upgrade to v25.1.0 or later.

Modification History

2025-08-26: Initial revision

Related Links

Acknowledgements

We thank the following parties for their efforts:

  • one of our Customers for reporting a bug, leading to Nozomi Networks confirming this issue

Contact

Nozomi Networks Product Security team can be reached at prodsec@nozominetworks.com.
More contact details on the PSIRT page.