CVE-2025-7039
Secure Connect Gateway: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CVE-2025-7039)
Affected
- NetApp/ActiveIQ Unified Manager
< *..9.13 - NetApp/ActiveIQ Unified Manager
< *..9.14 - NetApp/ActiveIQ Unified Manager
= 9.16..9.16 - Dell/Secure Connect Gateway
< *..5.36.00.16
Fixed in
- NetApp/ActiveIQ Unified Manager
9.13 - NetApp/ActiveIQ Unified Manager
9.14 - Dell/Secure Connect Gateway
5.36.00.16
Description
A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.
Source: BSI
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
< 5.36.00.16fixed in 5.36.00.169.16< 9.13fixed in 9.13< 9.14fixed in 9.14Metrics
Show all metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
References & sources
- https://access.redhat.com/security/cve/CVE-2025-7039vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2392423issue-trackingx_refsource_REDHAT
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
- https://github.com/google/security-research/security/advisories/GHSA-v2c8-vqqp-hv3g
- http://www.openwall.com/lists/oss-security/2025/09/06/2
- http://www.openwall.com/lists/oss-security/2025/11/18/10