Vulnerability Details CVE-2025-40898
A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a specifically-crafted Arc data archive, can potentially write arbitrary files in arbitrary paths, altering the device configuration and/or affecting its availability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.4%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2025-40898
-
cpe:2.3:a:nozominetworks:cmc:22.0.0
-
cpe:2.3:a:nozominetworks:cmc:22.5.2
-
cpe:2.3:a:nozominetworks:cmc:22.6.0
-
cpe:2.3:a:nozominetworks:cmc:22.6.2
-
cpe:2.3:a:nozominetworks:cmc:22.6.3
-
cpe:2.3:a:nozominetworks:cmc:23.0.0
-
cpe:2.3:a:nozominetworks:cmc:23.1.0
-
cpe:2.3:a:nozominetworks:cmc:23.3.0
-
cpe:2.3:a:nozominetworks:cmc:24.2.0
-
cpe:2.3:a:nozominetworks:cmc:25.2.0
-
cpe:2.3:a:nozominetworks:cmc:25.3.0
-
cpe:2.3:a:nozominetworks:guardian:19.0.4
-
cpe:2.3:a:nozominetworks:guardian:22.0.0
-
cpe:2.3:a:nozominetworks:guardian:22.5.2
-
cpe:2.3:a:nozominetworks:guardian:22.6.0
-
cpe:2.3:a:nozominetworks:guardian:22.6.2
-
cpe:2.3:a:nozominetworks:guardian:22.6.3
-
cpe:2.3:a:nozominetworks:guardian:23.0.0
-
cpe:2.3:a:nozominetworks:guardian:23.1.0
-
cpe:2.3:a:nozominetworks:guardian:23.3.0
-
cpe:2.3:a:nozominetworks:guardian:24.2.0
-
cpe:2.3:a:nozominetworks:guardian:25.2.0
-
cpe:2.3:a:nozominetworks:guardian:25.3.0