在 Dashboards(仪表盘)功能中发现了模板注入漏洞,原因是输入参数未进行适当验证。拥有相应权限的已认证用户可以定义包含恶意载荷的仪表盘,或者受害者可能被社会工程攻击诱导导入恶意仪表盘。当受害者查看或导入该仪表盘时,载荷将在其浏览器上下文中执行,使攻击者能够修改应用程序数据或破坏应用程序的可用性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nozomi Networks | CMC | < 26.3.0 |
affected |
| Nozomi Networks | Guardian | < 26.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nozomi Networks | Guardian | 0 ~ 26.3.0 | - |
|
| Nozomi Networks | CMC | 0 ~ 26.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33389 | 7.5 HIGH | Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian |
| CVE-2026-33388 | 7.4 HIGH | Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0 |
| CVE-2026-33391 | 5.4 MEDIUM | Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0 |
| CVE-2026-33920 | 3.5 LOW | Cross-site request forgery in the Guardian/CMC login before 26.3.0 |
No comments yet