Incorrect authorization in Secure Network Analytics Virtual Manager and Secure Network Analytics - CVE-2025-20257
Published: May 22, 2025
Vulnerability identifier: #VU109641
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20257
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to insufficient authorization enforcement in an API subsystem. A remote user can obfuscate legitimate findings in analytics reports or create false indications with alarms and alerts on the target device.
Affected software
Secure Network Analytics Virtual Manager
Secure Network Analytics
Secure Network Analytics
How to mitigate CVE-2025-20257
Install updates from vendor's website.
Secure Network Analytics Virtual Manager - update to 7.5.2 SMC ROLLUP20250416-01
Secure Network Analytics - update to 7.5.2 SMC ROLLUP20250416-01
Secure Network Analytics - update to 7.5.2 SMC ROLLUP20250416-01