Vulnerabilidades em Nozomi Networks

61 resultados
Análise Vexday

Nozomi Networks acumula 54 CVEs na base, com 11 publicadas nos últimos 90 dias, indicando ritmo sustentado de descobertas; nenhuma está sob ataque ativo (KEV), o que reduz a urgência imediata. A fraqueza dominante é injeção de script (CWE-79), padrão em aplicações web, com apenas 1 crítica catalogada, sugerindo risco moderado e previsível para quem mantém patching em dia.

CVE-2026-31985HIGHDisabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0EPSS 0.2%CVE-2025-40900MEDIUMAngular template injection in Reports in Guardian/CMC before 26.1.0EPSS 0.2%CVE-2025-40893MEDIUMHTML injection in Asset List in Guardian/CMC before 25.5.0EPSS 0.2%CVE-2025-40890MEDIUMStored Cross-Site Scripting (XSS) in Dashboards in Guardian/CMC before 25.4.0EPSS 0.2%CVE-2025-40903MEDIUMHTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0EPSS 0.2%CVE-2025-40901MEDIUMHTML injection in Credentials Manager in Guardian/CMC before 26.1.0EPSS 0.2%CVE-2025-40902MEDIUMHTML injection in Users in Guardian/CMC before 26.1.0EPSS 0.2%CVE-2025-40904MEDIUMHTML injection in Smart Polling in Guardian/CMC before 26.1.0EPSS 0.2%CVE-2025-40895LOWHTML injection in Sensor Map in CMC before 25.6.0EPSS 0.2%CVE-2025-40891LOWHTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0EPSS 0.2%CVE-2026-33922MEDIUMPath traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0EPSS 0.2%CVE-2025-40894LOWHTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0EPSS 0.2%CVE-2026-33389MEDIUMDisabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc before v2.7.0EPSS 0.2%CVE-2023-5935HIGHMissing authentication for local web interface in Arc before v1.6.0EPSS 0.2%CVE-2023-5936HIGHUnsafe temporary data privileges on Unix systems in Arc before v1.6.0EPSS 0.1%CVE-2023-24477MEDIUMSession Fixation in Guardian/CMC before 22.6.2EPSS 0.1%CVE-2023-5937MEDIUMSensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0EPSS 0.1%CVE-2024-13090HIGHPrivilege escalation in Guardian/CMC before 24.6.0EPSS 0.1%CVE-2026-33921MEDIUMNpcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0EPSS 0.1%CVE-2026-33920MEDIUMCross-site request forgery in the Guardian/CMC login before 26.3.0EPSS 0.1%