Incorrect authorization in Secure Network Analytics Virtual Manager and Secure Network Analytics - CVE-2025-20257

 

Incorrect authorization in Secure Network Analytics Virtual Manager and Secure Network Analytics - CVE-2025-20257

Published: May 22, 2025


Vulnerability identifier: #VU109641
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20257
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to insufficient authorization enforcement in an API subsystem. A remote user can obfuscate legitimate findings in analytics reports or create false indications with alarms and alerts on the target device.


Affected software

Secure Network Analytics Virtual Manager
Secure Network Analytics

How to mitigate CVE-2025-20257

Install updates from vendor's website.

Secure Network Analytics Virtual Manager - update to 7.5.2 SMC ROLLUP20250416-01
Secure Network Analytics - update to 7.5.2 SMC ROLLUP20250416-01

External References

Related Security Bulletins