CVE-2025-3719: Incorrect authorization for CLI in Guardian/CMC before 25.2.0
An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges can issue administrative CLI commands, altering the device configuration, and/or affecting its availability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3719?
CVE-2025-3719 is classified as a high severity vulnerability due to its potential for allowing unauthorized execution of administrative commands.
What does CVE-2025-3719 affect?
CVE-2025-3719 affects the Guardian CMC software, specifically versions up to 25.2.0.
How do I fix CVE-2025-3719?
To fix CVE-2025-3719, apply the latest security patches provided by Guardian for the CMC software.
What are the potential impacts of CVE-2025-3719?
The potential impacts of CVE-2025-3719 include unauthorized configuration changes that could compromise the security and integrity of the device.
Who is affected by CVE-2025-3719?
Authenticated users with limited privileges are affected by CVE-2025-3719 as they can exploit this vulnerability to issue administrative commands.