在“智能轮询”功能中发现了一个证书/主机密钥验证不当的漏洞。该功能在与目标设备建立加密连接时,未验证远程主机的身份,且未提供任何选项来启用该验证。位于传感器与被轮询设备之间的中间人攻击者,可以在轮询会话期间冒充该设备并截获通信内容,包括用于访问该设备的凭据。攻击者随后可以重放这些截获的凭据,直接对该设备本身或共享相同凭据的其他设备进行身份验证,从而访问并篡改设备数据,并干扰其正常运行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nozomi Networks | Arc | < 2.7.0 |
affected |
| Nozomi Networks | CMC | < 26.3.0 |
affected |
| Nozomi Networks | Guardian | < 26.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nozomi Networks | Guardian | 0 ~ 26.3.0 | - |
|
| Nozomi Networks | CMC | 0 ~ 26.3.0 | - |
|
| Nozomi Networks | Arc | 0 ~ 2.7.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33388 | 7.4 HIGH | Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0 |
| CVE-2026-33391 | 5.4 MEDIUM | Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0 |
| CVE-2026-33387 | 4.6 MEDIUM | Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0 |
| CVE-2026-33920 | 3.5 LOW | Cross-site request forgery in the Guardian/CMC login before 26.3.0 |
No comments yet