Vulnerability Details CVE-2025-49143
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to v2.4.10 and v1.6.32 , files uploaded by users to Nautobot's MEDIA_ROOT directory, including DeviceType image attachments as well as images attached to a Location, Device, or Rack, are served to users via a URL endpoint that was not enforcing user authentication. As a consequence, such files can be retrieved by anonymous users who know or can guess the correct URL for a given file. Nautobot v2.4.10 and v1.6.32 address this issue by adding enforcement of Nautobot user authentication to this endpoint.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.6%
CVSS Severity
CVSS v3 Score 5.9
Products affected by CVE-2025-49143
-
cpe:2.3:a:networktocode:nautobot:-
-
cpe:2.3:a:networktocode:nautobot:1.0.0
-
cpe:2.3:a:networktocode:nautobot:1.0.1
-
cpe:2.3:a:networktocode:nautobot:1.0.2
-
cpe:2.3:a:networktocode:nautobot:1.0.3
-
cpe:2.3:a:networktocode:nautobot:1.1.0
-
cpe:2.3:a:networktocode:nautobot:1.1.1
-
cpe:2.3:a:networktocode:nautobot:1.1.2
-
cpe:2.3:a:networktocode:nautobot:1.1.3
-
cpe:2.3:a:networktocode:nautobot:1.1.4
-
cpe:2.3:a:networktocode:nautobot:1.1.5
-
cpe:2.3:a:networktocode:nautobot:1.1.6
-
cpe:2.3:a:networktocode:nautobot:1.2.0
-
cpe:2.3:a:networktocode:nautobot:1.2.1
-
cpe:2.3:a:networktocode:nautobot:1.2.10
-
cpe:2.3:a:networktocode:nautobot:1.2.11
-
cpe:2.3:a:networktocode:nautobot:1.2.2
-
cpe:2.3:a:networktocode:nautobot:1.2.3
-
cpe:2.3:a:networktocode:nautobot:1.2.4
-
cpe:2.3:a:networktocode:nautobot:1.2.5
-
cpe:2.3:a:networktocode:nautobot:1.2.6
-
cpe:2.3:a:networktocode:nautobot:1.2.7
-
cpe:2.3:a:networktocode:nautobot:1.2.8
-
cpe:2.3:a:networktocode:nautobot:1.2.9
-
cpe:2.3:a:networktocode:nautobot:1.3.0
-
cpe:2.3:a:networktocode:nautobot:1.3.1
-
cpe:2.3:a:networktocode:nautobot:1.3.10
-
cpe:2.3:a:networktocode:nautobot:1.3.2
-
cpe:2.3:a:networktocode:nautobot:1.3.3
-
cpe:2.3:a:networktocode:nautobot:1.3.4
-
cpe:2.3:a:networktocode:nautobot:1.3.5
-
cpe:2.3:a:networktocode:nautobot:1.3.6
-
cpe:2.3:a:networktocode:nautobot:1.3.7
-
cpe:2.3:a:networktocode:nautobot:1.3.8
-
cpe:2.3:a:networktocode:nautobot:1.3.9
-
cpe:2.3:a:networktocode:nautobot:1.4.0
-
cpe:2.3:a:networktocode:nautobot:1.4.1
-
cpe:2.3:a:networktocode:nautobot:1.4.10
-
cpe:2.3:a:networktocode:nautobot:1.4.2
-
cpe:2.3:a:networktocode:nautobot:1.4.3
-
cpe:2.3:a:networktocode:nautobot:1.4.4
-
cpe:2.3:a:networktocode:nautobot:1.4.5
-
cpe:2.3:a:networktocode:nautobot:1.4.6
-
cpe:2.3:a:networktocode:nautobot:1.4.7
-
cpe:2.3:a:networktocode:nautobot:1.4.8
-
cpe:2.3:a:networktocode:nautobot:1.4.9
-
cpe:2.3:a:networktocode:nautobot:1.5.0
-
cpe:2.3:a:networktocode:nautobot:1.5.1
-
cpe:2.3:a:networktocode:nautobot:1.5.10
-
cpe:2.3:a:networktocode:nautobot:1.5.11
-
cpe:2.3:a:networktocode:nautobot:1.5.12
-
cpe:2.3:a:networktocode:nautobot:1.5.13
-
cpe:2.3:a:networktocode:nautobot:1.5.14
-
cpe:2.3:a:networktocode:nautobot:1.5.15
-
cpe:2.3:a:networktocode:nautobot:1.5.16
-
cpe:2.3:a:networktocode:nautobot:1.5.17
-
cpe:2.3:a:networktocode:nautobot:1.5.18
-
cpe:2.3:a:networktocode:nautobot:1.5.19
-
cpe:2.3:a:networktocode:nautobot:1.5.2
-
cpe:2.3:a:networktocode:nautobot:1.5.20
-
cpe:2.3:a:networktocode:nautobot:1.5.21
-
cpe:2.3:a:networktocode:nautobot:1.5.22
-
cpe:2.3:a:networktocode:nautobot:1.5.23
-
cpe:2.3:a:networktocode:nautobot:1.5.24
-
cpe:2.3:a:networktocode:nautobot:1.5.3
-
cpe:2.3:a:networktocode:nautobot:1.5.4
-
cpe:2.3:a:networktocode:nautobot:1.5.5
-
cpe:2.3:a:networktocode:nautobot:1.5.6
-
cpe:2.3:a:networktocode:nautobot:1.5.7
-
cpe:2.3:a:networktocode:nautobot:1.5.8
-
cpe:2.3:a:networktocode:nautobot:1.5.9
-
cpe:2.3:a:networktocode:nautobot:1.6.0
-
cpe:2.3:a:networktocode:nautobot:1.6.1
-
cpe:2.3:a:networktocode:nautobot:1.6.10
-
cpe:2.3:a:networktocode:nautobot:1.6.11
-
cpe:2.3:a:networktocode:nautobot:1.6.12
-
cpe:2.3:a:networktocode:nautobot:1.6.13
-
cpe:2.3:a:networktocode:nautobot:1.6.14
-
cpe:2.3:a:networktocode:nautobot:1.6.15
-
cpe:2.3:a:networktocode:nautobot:1.6.16
-
cpe:2.3:a:networktocode:nautobot:1.6.17
-
cpe:2.3:a:networktocode:nautobot:1.6.18
-
cpe:2.3:a:networktocode:nautobot:1.6.19
-
cpe:2.3:a:networktocode:nautobot:1.6.2
-
cpe:2.3:a:networktocode:nautobot:1.6.20
-
cpe:2.3:a:networktocode:nautobot:1.6.21
-
cpe:2.3:a:networktocode:nautobot:1.6.22
-
cpe:2.3:a:networktocode:nautobot:1.6.23
-
cpe:2.3:a:networktocode:nautobot:1.6.24
-
cpe:2.3:a:networktocode:nautobot:1.6.25
-
cpe:2.3:a:networktocode:nautobot:1.6.26
-
cpe:2.3:a:networktocode:nautobot:1.6.27
-
cpe:2.3:a:networktocode:nautobot:1.6.28
-
cpe:2.3:a:networktocode:nautobot:1.6.3
-
cpe:2.3:a:networktocode:nautobot:1.6.4
-
cpe:2.3:a:networktocode:nautobot:1.6.5
-
cpe:2.3:a:networktocode:nautobot:1.6.6
-
cpe:2.3:a:networktocode:nautobot:1.6.7
-
cpe:2.3:a:networktocode:nautobot:1.6.8
-
cpe:2.3:a:networktocode:nautobot:1.6.9
-
cpe:2.3:a:networktocode:nautobot:2.0.0
-
cpe:2.3:a:networktocode:nautobot:2.0.1
-
cpe:2.3:a:networktocode:nautobot:2.0.2
-
cpe:2.3:a:networktocode:nautobot:2.0.3
-
cpe:2.3:a:networktocode:nautobot:2.0.4
-
cpe:2.3:a:networktocode:nautobot:2.0.5
-
cpe:2.3:a:networktocode:nautobot:2.0.6
-
cpe:2.3:a:networktocode:nautobot:2.1.0
-
cpe:2.3:a:networktocode:nautobot:2.1.1
-
cpe:2.3:a:networktocode:nautobot:2.1.2
-
cpe:2.3:a:networktocode:nautobot:2.1.3
-
cpe:2.3:a:networktocode:nautobot:2.1.4
-
cpe:2.3:a:networktocode:nautobot:2.1.5
-
cpe:2.3:a:networktocode:nautobot:2.1.6
-
cpe:2.3:a:networktocode:nautobot:2.1.7
-
cpe:2.3:a:networktocode:nautobot:2.1.8
-
cpe:2.3:a:networktocode:nautobot:2.1.9
-
cpe:2.3:a:networktocode:nautobot:2.2.0
-
cpe:2.3:a:networktocode:nautobot:2.2.1
-
cpe:2.3:a:networktocode:nautobot:2.2.2
-
cpe:2.3:a:networktocode:nautobot:2.2.3
-
cpe:2.3:a:networktocode:nautobot:2.2.4
-
cpe:2.3:a:networktocode:nautobot:2.2.5
-
cpe:2.3:a:networktocode:nautobot:2.2.6
-
cpe:2.3:a:networktocode:nautobot:2.2.7
-
cpe:2.3:a:networktocode:nautobot:2.2.8
-
cpe:2.3:a:networktocode:nautobot:2.2.9
-
cpe:2.3:a:networktocode:nautobot:2.3.0
-
cpe:2.3:a:networktocode:nautobot:2.3.1
-
cpe:2.3:a:networktocode:nautobot:2.3.2
-
cpe:2.3:a:networktocode:nautobot:2.3.3
-
cpe:2.3:a:networktocode:nautobot:2.3.4
-
cpe:2.3:a:networktocode:nautobot:2.3.5
-
cpe:2.3:a:networktocode:nautobot:2.3.6
-
cpe:2.3:a:networktocode:nautobot:2.3.7
-
cpe:2.3:a:networktocode:nautobot:2.3.8
-
cpe:2.3:a:networktocode:nautobot:2.3.9