CVE-2025-7709

Secure Connect Gateway: Integer Overflow or Wraparound (CVE-2025-7709)

mediumEPSS 0.4%

Affected

  • NetApp/ActiveIQ Unified Manager < *..9.13
  • NetApp/ActiveIQ Unified Manager < *..9.14
  • NetApp/ActiveIQ Unified Manager = 9.16..9.16
  • Dell/Secure Connect Gateway < *..5.36.00.16

Fixed in

  • NetApp/ActiveIQ Unified Manager 9.13
  • NetApp/ActiveIQ Unified Manager 9.14
  • Dell/Secure Connect Gateway 5.36.00.16

Description

An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

DellSecure Connect Gateway
< 5.36.00.16fixed in 5.36.00.16
NetAppActiveIQ Unified Manager
9.16< 9.13fixed in 9.13< 9.14fixed in 9.14

Metrics

6.9
Source: nvd-v4
26.9 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-09-08 14:51 UTC
CWE-190

Weakness classes (CWE)

  • CWE-190Base

    Integer Overflow or Wraparound

    The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

    cwe.mitre.org →

References & sources