Vulnerabilidades em Nozomi Networks
54 resultadosAnálise Vexday
Nozomi Networks acumula 54 CVEs na base, com 11 publicadas nos últimos 90 dias, indicando ritmo sustentado de descobertas; nenhuma está sob ataque ativo (KEV), o que reduz a urgência imediata. A fraqueza dominante é injeção de script (CWE-79), padrão em aplicações web, com apenas 1 crítica catalogada, sugerindo risco moderado e previsível para quem mantém patching em dia.
CVE-2025-40904MEDIUMHTML injection in Smart Polling in Guardian/CMC before 26.1.0EPSS 0.2%CVE-2025-40895LOWHTML injection in Sensor Map in CMC before 25.6.0EPSS 0.2%CVE-2025-40893MEDIUMHTML injection in Asset List in Guardian/CMC before 25.5.0EPSS 0.2%CVE-2026-31982MEDIUMOpen Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0EPSS 0.2%CVE-2025-40894LOWHTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0EPSS 0.2%CVE-2023-5935HIGHMissing authentication for local web interface in Arc before v1.6.0EPSS 0.2%CVE-2025-40891LOWHTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0EPSS 0.2%CVE-2023-5936HIGHUnsafe temporary data privileges on Unix systems in Arc before v1.6.0EPSS 0.1%CVE-2023-5937MEDIUMSensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0EPSS 0.1%CVE-2026-31981MEDIUMHTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0EPSS 0.1%CVE-2023-24477MEDIUMSession Fixation in Guardian/CMC before 22.6.2EPSS 0.1%CVE-2026-31985HIGHDisabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0EPSS 0.1%CVE-2024-13090HIGHPrivilege escalation in Guardian/CMC before 24.6.0EPSS 0.1%CVE-2025-40896MEDIUMLack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before v2.2.0EPSS 0.1%