Nozomi Networks Guardian/CMC是美国Nozomi Networks公司的一个中央管理控制台。 Nozomi Networks Guardian/CMC存在SQL注入漏洞,该漏洞源于Alert功能中输入参数验证不当,可能导致SQL注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nozomi Networks | Guardian | 0 ~ 25.2.0 | - |
|
| Nozomi Networks | CMC | 0 ~ 25.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-40889 | 8.1 HIGH | Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0 |
| CVE-2025-3719 | 8.1 HIGH | Incorrect authorization for CLI in Guardian/CMC before 25.2.0 |
| CVE-2025-3718 | 7.9 HIGH | Client-side path traversal in Guardian/CMC before 25.2.0 |
| CVE-2025-40886 | 7.5 HIGH | Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0 |
| CVE-2025-40885 | 5.3 MEDIUM | Authenticated SQL Injection on Smart Polling functionality in Guardian/CMC before 25.2.0 |
| CVE-2025-40888 | 5.3 MEDIUM | Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0 |
No comments yet