An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to improper access restrictions, potentially exposing unauthorized network data.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://security.nozominetworks.com/NN-2025:3-01 |
|
History
Wed, 27 Aug 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nozominetworks
Nozominetworks cmc |
|
| Vendors & Products |
Nozominetworks
Nozominetworks cmc |
Tue, 26 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 Aug 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to improper access restrictions, potentially exposing unauthorized network data. | |
| Title | Incorrect authorization for traces request/download in CMC before 25.1.0 | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Nozomi
Published: 2025-08-26T10:25:47.063Z
Updated: 2025-08-26T15:19:46.745Z
Reserved: 2025-02-20T16:17:04.011Z
Link: CVE-2025-1501
Updated: 2025-08-26T15:16:35.366Z
Status : Awaiting Analysis
Published: 2025-08-26T11:15:31.773
Modified: 2025-08-26T13:41:58.950
Link: CVE-2025-1501
No data.