Vulnerabilidades en Nozomi Networks

61 resultados
Análisis Vexday

Nozomi Networks acumula 54 CVEs na base, com 11 publicadas nos últimos 90 dias, indicando ritmo sustentado de descobertas; nenhuma está sob ataque ativo (KEV), o que reduz a urgência imediata. A fraqueza dominante é injeção de script (CWE-79), padrão em aplicações web, com apenas 1 crítica catalogada, sugerindo risco moderado e previsível para quem mantém patching em dia.

CVE-2025-40889HIGHPath traversal in Time Machine functionality in Guardian/CMC before 25.2.0EPSS 0.4%CVE-2025-40898HIGHPath traversal in Import Arc data archive functionality in Guardian/CMC before 25.5.0EPSS 0.4%CVE-2026-33390HIGHIncorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0EPSS 0.4%CVE-2026-33388MEDIUMIncorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0EPSS 0.4%CVE-2026-33391MEDIUMIncorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0EPSS 0.3%CVE-2023-22843HIGHStored Cross-Site Scripting (XSS) in Threat Intelligence rules in Guardian/CMC before 22.6.2EPSS 0.3%CVE-2025-40897HIGHIncorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0EPSS 0.3%CVE-2026-31982MEDIUMOpen Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0EPSS 0.3%CVE-2025-40899HIGHStored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0EPSS 0.3%CVE-2025-3719HIGHIncorrect authorization for CLI in Guardian/CMC before 25.2.0EPSS 0.3%CVE-2025-40886HIGHAuthenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0EPSS 0.3%CVE-2025-40892HIGHStored Cross-Site Scripting (XSS) in Reports in Guardian/CMC before 25.5.0EPSS 0.3%CVE-2026-31981MEDIUMHTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0EPSS 0.3%CVE-2026-33387MEDIUMInsufficient sanitization of Dashboards in Guardian/CMC before 26.3.0EPSS 0.2%CVE-2025-40885MEDIUMAuthenticated SQL Injection on Smart Polling functionality in Guardian/CMC before 25.2.0EPSS 0.2%CVE-2025-40887MEDIUMAuthenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0EPSS 0.2%CVE-2025-40888MEDIUMAuthenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0EPSS 0.2%CVE-2025-3718MEDIUMClient-side path traversal in Guardian/CMC before 25.2.0EPSS 0.2%CVE-2024-4465MEDIUMIncorrect authorization for Reports configuration in Guardian/CMC before 24.2.0EPSS 0.2%CVE-2025-1501MEDIUMIncorrect authorization for traces request/download in CMC before 25.1.0EPSS 0.2%