Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27682 | An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to improper access restrictions, potentially exposing unauthorized network data. |
Solution
Upgrade to v25.1.0 or later.
Workaround
Use internal firewall features to limit access to the web management interface.
| Link | Providers |
|---|---|
| https://security.nozominetworks.com/NN-2025:3-01 |
|
Wed, 27 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nozominetworks
Nozominetworks cmc |
|
| Vendors & Products |
Nozominetworks
Nozominetworks cmc |
Tue, 26 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 Aug 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to improper access restrictions, potentially exposing unauthorized network data. | |
| Title | Incorrect authorization for traces request/download in CMC before 25.1.0 | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2025-08-26T15:19:46.745Z
Reserved: 2025-02-20T16:17:04.011Z
Link: CVE-2025-1501
Updated: 2025-08-26T15:16:35.366Z
Status : Awaiting Analysis
Published: 2025-08-26T11:15:31.773
Modified: 2025-08-26T13:41:58.950
Link: CVE-2025-1501
No data.
OpenCVE Enrichment
Updated: 2025-08-27T11:41:43Z
EUVD