在凭据管理器(Credentials Manager)功能中,由于对用户权限的校验不足,发现了一个访问控制漏洞。一个拥有受限权限的远程认证用户能够查看可用凭据条目的一个有限子集。虽然实际的凭据值不会直接可见,但该用户仍然可以删除条目或编辑其属性。攻击者如果删除或编辑某个条目,可能会中断依赖该凭据的设备的认证过程;而如果攻击者能够操纵某个条目的配置,则可能间接获取其中的凭据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nozomi Networks | CMC | < 26.3.0 |
affected |
| Nozomi Networks | Guardian | < 26.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nozomi Networks | Guardian | 0 ~ 26.3.0 | - |
|
| Nozomi Networks | CMC | 0 ~ 26.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33389 | 7.5 HIGH | Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian |
| CVE-2026-33391 | 5.4 MEDIUM | Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0 |
| CVE-2026-33387 | 4.6 MEDIUM | Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0 |
| CVE-2026-33920 | 3.5 LOW | Cross-site request forgery in the Guardian/CMC login before 26.3.0 |
No comments yet