NN-2025:9-01

Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0

Last update: 2025-10-07

Advisory IDNN-2025:9-01
TopicPath traversal in Time Machine functionality in Guardian/CMC before 25.2.0
CWE ImpactCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Issue date2025-10-07
AffectsGuardian, CMC < v25.2.0
CVE Name(s)CVE-2025-40889
CVSS DetailsCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVSS Score7.2 (CVSS v4.0)
8.1 (CVSS v3.1)
CVE Risk LevelHigh (CVSS v4.0)
High (CVSS v3.1)
Risk Level for Nozomi customersMedium

Summary

A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters.

Impact

An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their availability.

Affected Products

Guardian, CMC < v25.2.0

Workarounds and Mitigations

Use internal firewall features to limit access to the web management interface. Review all accounts with access to it and delete unnecessary ones.

Solutions

Upgrade to v25.2.0 or later.

Modification History

2025-10-07: Initial revision

Related Links

Acknowledgements

We thank the following parties for their efforts:

  • Andrea Palanca of Nozomi Networks Product Security team for finding this issue during an internal investigation

Contact

Nozomi Networks Product Security team can be reached at prodsec@nozominetworks.com.
More contact details on the PSIRT page.