Nozomi Networks Guardian是美国Nozomi Networks公司的网络安全产品。 Nozomi Networks Guardian 26.2.0之前版本和CMC 26.2.0之前版本存在权限许可和访问控制问题漏洞,该漏洞源于同步功能中Arc sensors接收CLI权限导致权限分配错误,可能允许经过身份验证的有限权限用户通过同步推送管理CLI命令,从而更改设备配置和/或影响其可用性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nozomi Networks | CMC | < 26.2.0 |
affected |
| Nozomi Networks | Guardian | < 26.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nozomi Networks | Guardian | 0 ~ 26.2.0 | - |
|
| Nozomi Networks | CMC | 0 ~ 26.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-31985 | 8.1 HIGH | Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the R |
| CVE-2026-31984 | 7.5 HIGH | DoS through oversized audit log entries in Guardian/CMC before 26.2.0 |
| CVE-2026-31982 | 7.1 HIGH | Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0 |
| CVE-2026-31981 | 5.9 MEDIUM | HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0 |
| CVE-2026-31983 | 5.3 MEDIUM | Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0 |
No comments yet