« Volver al listado

Nozominetworks

Nozominetworks CMC: vulnerabilidades y CVE

Nozominetworks CMC tiene 40 vulnerabilidades publicadas, 23 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE40
Últimos 12 meses23
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-33390Alta (7.2)0.40%—9 jul 2026
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI…
CVE-2026-31984Alta (8.7)0.51%—9 jul 2026
A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker…
CVE-2026-31983Media (6.9)0.44%—9 jul 2026
A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that…
CVE-2026-31982Media (5.3)0.31%—9 jul 2026
An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the…
CVE-2026-31981Media (4.8)0.25%—9 jul 2026
A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can…
CVE-2025-40904Media (5.1)0.19%—19 may 2026
A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote…
CVE-2025-40903Media (4.8)0.19%—19 may 2026
A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a…
CVE-2025-40902Media (4.8)0.19%—19 may 2026
A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose…
CVE-2025-40901Media (4.8)0.19%—19 may 2026
A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious…
CVE-2025-40900Media (5.1)0.20%—19 may 2026
An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report…
CVE-2025-40895Baja (2)0.18%—4 mar 2026
A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on connected Guardians' properties. A malicious authenticated user with administrator privileges on a…
CVE-2025-40894Baja (2.1)0.17%—4 mar 2026
A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation on an input parameter. A malicious authenticated user with the required privileges could edit…
CVE-2025-40898Alta (7.2)0.40%—18 dic 2025
A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited privileges, by uploading a…
CVE-2025-40893Media (5.3)0.20%—18 dic 2025
A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject…
CVE-2025-40892Alta (7.1)0.26%—18 dic 2025
A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report…
CVE-2025-40891Baja (2.3)0.18%—18 dic 2025
A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network…
CVE-2025-40889Alta (7.2)0.41%—7 oct 2025
A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated user with limited privileges, by issuing a specifically-crafted…
CVE-2025-40888Media (6)0.24%—7 oct 2025
A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the…
CVE-2025-40887Media (6)0.24%—7 oct 2025
A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the…
CVE-2025-40886Alta (7.7)0.27%—7 oct 2025
A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SQL statements on the DBMS…
CVE-2025-40885Media (6)0.24%—7 oct 2025
A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements…
CVE-2025-3719Alta (7.2)0.27%—7 oct 2025
An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authenticated user with limited privileges…
CVE-2025-3718Media (5.9)0.22%—7 oct 2025
A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. An authenticated user with limited privileges can craft a malicious…
CVE-2025-1501Media (5.3)0.21%—26 ago 2025
An access control vulnerability was discovered in the Request Trace and Download Trace functionalities of CMC before 25.1.0 due to a specific access restriction not being properly enforced for users with limited…
CVE-2024-13089Alta (7.5)1.0%—10 jun 2025
An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS commands. Users with administrative privileges may upload update…
CVE-2024-4465Media (5.8)0.22%—11 sept 2024
An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with reporting privileges…
CVE-2023-5253Media (6.3)0.45%—15 ene 2024
A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication.…
CVE-2023-32649Alta (8.2)0.64%—19 sept 2023
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, allows an unauthenticated attacker…
CVE-2023-2567Alta (8.7)0.62%—19 sept 2023
A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality. Authenticated users may be able to execute…
CVE-2023-29245Crítica (9.2)0.60%—19 sept 2023
A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services6
  2. T1005 Data from Local System1
  3. T1059 Command and Scripting Interpreter1
  4. T1059.007 JavaScript1
  5. T1078 Valid Accounts1
  6. T1189 Drive-by Compromise1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Nozominetworks