An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to improper access restrictions, potentially exposing unauthorized network data.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://security.nozominetworks.com/NN-2025:3-01 |
![]() ![]() |
History
Tue, 26 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 26 Aug 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can request and download trace files due to improper access restrictions, potentially exposing unauthorized network data. | |
Title | Incorrect authorization for traces request/download in CMC before 25.1.0 | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Nozomi
Published: 2025-08-26T10:25:47.063Z
Updated: 2025-08-26T15:19:46.745Z
Reserved: 2025-02-20T16:17:04.011Z
Link: CVE-2025-1501

Updated: 2025-08-26T15:16:35.366Z

Status : Awaiting Analysis
Published: 2025-08-26T11:15:31.773
Modified: 2025-08-26T13:41:58.950
Link: CVE-2025-1501

No data.