在 Smart Polling(智能轮询)配置功能中发现了一个访问控制漏洞,原因是未充分校验用户权限。一个拥有有限权限的已认证用户可以远程绕过 Web 管理界面的预期访问控制,从而修改智能轮询的发现配置。这使得攻击者能够干扰受监控网络中资产的可观测性(可见性)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nozomi Networks | CMC | < 26.3.0 |
affected |
| Nozomi Networks | Guardian | < 26.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nozomi Networks | Guardian | 0 ~ 26.3.0 | - |
|
| Nozomi Networks | CMC | 0 ~ 26.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33389 | 7.5 HIGH | Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian |
| CVE-2026-33388 | 7.4 HIGH | Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0 |
| CVE-2026-33387 | 4.6 MEDIUM | Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0 |
| CVE-2026-33920 | 3.5 LOW | Cross-site request forgery in the Guardian/CMC login before 26.3.0 |
No comments yet