CVE-2025-7039

Secure Connect Gateway: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2025-7039)

Affected

  • NetApp/ActiveIQ Unified Manager < *..9.13
  • NetApp/ActiveIQ Unified Manager < *..9.14
  • NetApp/ActiveIQ Unified Manager = 9.16..9.16
  • Dell/Secure Connect Gateway < *..5.36.00.16

Fixed in

  • NetApp/ActiveIQ Unified Manager 9.13
  • NetApp/ActiveIQ Unified Manager 9.14
  • Dell/Secure Connect Gateway 5.36.00.16

Description

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

DellSecure Connect Gateway
< 5.36.00.16fixed in 5.36.00.16
NetAppActiveIQ Unified Manager
9.16< 9.13fixed in 9.13< 9.14fixed in 9.14

Metrics

3.7
Source: nvd-v3
31.8 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
low
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-09-03 01:52 UTC
CWE-22

Weakness classes (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

References & sources