Impact
The flaw is a path traversal bug in the offline archives component of the Arc local web interface; it allows a user who has local administrative rights to provide an archive name containing traversal sequences that cause the Arc process, which runs with elevated host privileges, to delete arbitrary files within its file system. This can erase critical configuration, backup, or operational files and disrupt device functionality.
Affected Systems
All Nozomi Networks Arc deployments running any version earlier than 2.7.0 that expose the local web interface are affected. The vulnerability resides in the offline archives feature and requires local access to the web interface.
Risk and Exploitability
The CVSS score of 6.8 places the flaw in the medium severity range. Because the attack requires local administrative access to the web interface and no publicly documented exploitation exists (EPSS is not available and it is not listed in the CISA KEV catalog), the likelihood of exploitation is limited to environments where an attacker can gain local admin credentials. If such credentials are in use, the attacker can delete any file reachable by the Arc process, potentially compromising device operation or data integrity.
OpenCVE Enrichment