CVE-2025-40889: Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0
A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted request, can potentially alter the structure and content of files in the /data folder, and/or affect their availability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40889?
CVE-2025-40889 is classified as a high-severity vulnerability due to its potential impact on file integrity.
How do I fix CVE-2025-40889?
To fix CVE-2025-40889, ensure proper validation of input parameters in the Time Machine functionality.
Who is affected by CVE-2025-40889?
CVE-2025-40889 affects users of Guardian CMC versions up to 25.2.0.
What type of vulnerability is CVE-2025-40889?
CVE-2025-40889 is a path traversal vulnerability that allows unauthorized manipulation of files.
What can an attacker do with CVE-2025-40889?
An attacker can potentially alter the structure and content of files by exploiting CVE-2025-40889.