在登录功能(包括标准登录和SAML登录)中发现了跨站请求伪造(CSRF)漏洞,原因是缺少对防CSRF令牌(anti-CSRF token)的校验。拥有有效账户的攻击者可以诱使受害者不知晓的情况下,使用攻击者的身份凭证进行认证。在这种状态下,受害者执行的任何操作都会被归因于攻击者的账户,从而破坏了审计追踪记录的完整性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nozomi Networks | CMC | < 26.3.0 |
affected |
| Nozomi Networks | Guardian | < 26.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nozomi Networks | Guardian | 0 ~ 26.3.0 | - |
|
| Nozomi Networks | CMC | 0 ~ 26.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33389 | 7.5 HIGH | Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian |
| CVE-2026-33388 | 7.4 HIGH | Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0 |
| CVE-2026-33391 | 5.4 MEDIUM | Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0 |
| CVE-2026-33387 | 4.6 MEDIUM | Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0 |
No comments yet