Nozomi Networks Guardian和Nozomi Networks CMC都是美国Nozomi Networks公司的产品。Nozomi Networks Guardian是一款物联网设备和软件检查系统。Nozomi Networks CMC是一个应用软件。提供集中的OT和IoT安全管理。 Nozomi Networks Guardian和Nozomi Networks CMC存在路径遍历漏洞,该漏洞源于缺少对两个输入参数的验证,可能导致路径遍历攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nozomi Networks | Guardian | 0 ~ 25.2.0 | - |
|
| Nozomi Networks | CMC | 0 ~ 25.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-3719 | 8.1 HIGH | Incorrect authorization for CLI in Guardian/CMC before 25.2.0 |
| CVE-2025-3718 | 7.9 HIGH | Client-side path traversal in Guardian/CMC before 25.2.0 |
| CVE-2025-40886 | 7.5 HIGH | Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0 |
| CVE-2025-40885 | 5.3 MEDIUM | Authenticated SQL Injection on Smart Polling functionality in Guardian/CMC before 25.2.0 |
| CVE-2025-40888 | 5.3 MEDIUM | Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0 |
| CVE-2025-40887 | 5.3 MEDIUM | Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0 |
No comments yet