← Retour aux CVEs
CVE-2025-40898
HIGH8.1
Description
A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device configuration and/or affecting its availability.
Details CVE
Score CVSS v3.18.1
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie12/18/2025
Derniere modification4/14/2026
Sourcenvd
Observations honeypot0
Produits affectes
nozominetworks:cmcnozominetworks:guardian
Faiblesses (CWE)
CWE-22
References
https://security.nozominetworks.com/NN-2025:15-01(prodsec@nozominetworks.com)
https://cert-portal.siemens.com/productcert/html/ssa-827968.html(0b142b55-0307-4c5a-b3c9-f314f3fb7c5e)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.