Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Guardian — Vulnerabilities & Security Advisories 57

All 57 CVE vulnerabilities found in Guardian, with AI-generated Chinese analysis, references, and POCs.

This page documents vulnerability aggregation data for Guardian, a software product from its respective vendor, focusing on common weakness enumeration and related security tags. It collects a comprehensive range of vulnerability reports, including remote code execution flaws, authentication bypasses, and information disclosure issues, covering incidents reported from 2018 through the present day. The dataset is structured to help security professionals and risk managers effectively track vendor-specific advisories as they are issued, understand the broader implications of specific weakness classes within the Guardian ecosystem, and look up a product’s complete vulnerability history to assess long-term security posture. By centralizing these records, the page serves as a reference point for identifying patterns in defect types and evaluating the vendor’s response timeline. This information supports due diligence processes, third-party risk assessments, and internal security audits by providing transparent access to past security events. The data includes metadata such as release versions affected, severity ratings, and patch availability status, allowing users to correlate technical details with business impact. Users are encouraged to cross-reference this aggregation with official vendor channels for the most current mitigation guidance and to consult internal threat intelligence feeds for real-time monitoring alerts. This resource aims to streamline the review of historical security incidents and facilitate informed decision-making regarding upgrade cycles and remediation priorities.

Vendor: Nozomi Networks

CVE ID Title CVSS Severity Published
CVE-2025-40888 Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0 CWE-89 5.3 Medium 2025-10-07
CVE-2025-40889 Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0 CWE-22 8.1 High 2025-10-07
CVE-2025-40887 Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0 CWE-89 5.3 Medium 2025-10-07
CVE-2025-40886 Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0 CWE-89 7.5 High 2025-10-07
CVE-2025-40885 Authenticated SQL Injection on Smart Polling functionality in Guardian/CMC before 25.2.0 CWE-89 5.3 Medium 2025-10-07
CVE-2025-3719 Incorrect authorization for CLI in Guardian/CMC before 25.2.0 CWE-863 8.1 High 2025-10-07
CVE-2025-3718 Client-side path traversal in Guardian/CMC before 25.2.0 CWE-22 7.9 High 2025-10-07
CVE-2024-13090 Privilege escalation in Guardian/CMC before 24.6.0 CWE-250 7.0 High 2025-06-10
CVE-2024-13089 Authenticated RCE in update functionality in Guardian/CMC before 24.6.0 CWE-78 7.2 High 2025-06-10
CVE-2024-4465 Incorrect authorization for Reports configuration in Guardian/CMC before 24.2.0 CWE-863 6.0 Medium 2024-09-11
CVE-2024-0218 DoS on IDS parsing of malformed Radius packets in Guardian before 23.4.1 CWE-1286 7.5 High 2024-04-10
CVE-2023-6916 Information disclosure via audit records for OpenAPI requests in Guardian/CMC before 23.4.1 CWE-201 7.2 High 2024-04-10
CVE-2023-5253 Check Point IoT integration: WebSocket returns assets data without authentication in Guardian/CMC before 23.3.0 CWE-306 5.3 Medium 2024-01-15
CVE-2023-32649 DoS on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0 CWE-1286 7.5 High 2023-09-19
CVE-2023-29245 SQL Injection on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0 CWE-89 8.1 High 2023-09-19
CVE-2023-2567 Authenticated SQL Injection on Query functionality in Guardian/CMC before 22.6.3 and 23.1.0 CWE-89 8.8 High 2023-09-19
CVE-2023-23903 DoS via SAML configuration in Guardian/CMC before 22.6.2 CWE-1286 4.9 Medium 2023-08-09
CVE-2023-24015 Partial DoS on Reports section due to null report name in Guardian/CMC before 22.6.2 CWE-1286 4.3 Medium 2023-08-09
CVE-2023-24471 Information disclosure via the debug function in assertions in Guardian/CMC before 22.6.2 CWE-863 6.5 Medium 2023-08-09
CVE-2023-22843 Stored Cross-Site Scripting (XSS) in Threat Intelligence rules in Guardian/CMC before 22.6.2 CWE-79 6.4 Medium 2023-08-09
CVE-2023-23574 Authenticated Blind SQL Injection on alerts count in Guardian/CMC before 22.6.2 CWE-89 8.8 High 2023-08-09
CVE-2023-22378 Authenticated Blind SQL Injection on sorting in Guardian/CMC before 22.6.2 CWE-89 8.8 High 2023-08-09
CVE-2023-24477 Session Fixation in Guardian/CMC before 22.6.2 CWE-384 7.0 High 2023-08-09
CVE-2022-0551 Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0 CWE-20 7.2 High 2022-03-24
CVE-2022-0550 Authenticated RCE on logo report upload in Guardian/CMC before 22.0.0 CWE-20 7.2 High 2022-03-24
CVE-2021-26724 Authenticated command injection when changing date settings or hostname in Guardian/CMC before 20.0.7.4 CWE-78 7.2 High 2021-02-22
CVE-2021-26725 Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4 CWE-24 7.2 High 2021-02-22

All 57 known CVE vulnerabilities affecting Guardian with full Chinese analysis, references, and POCs where available.