Nozomi Networks CMC是美国Nozomi Networks公司的一款网络管理平台。 Nozomi Networks CMC存在跨站脚本漏洞,该漏洞源于CMC Sensor Map功能对连接Guardian的属性验证不当,可能导致具有管理员权限的恶意用户注入HTML标签并实施钓鱼或开放重定向攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nozomi Networks | CMC | 0 ~ 25.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-40896 | 6.5 MEDIUM | Lack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before |
| CVE-2025-40894 | 4.4 MEDIUM | HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0 |
No comments yet