Page 2 of 20 results (0.003 seconds)

CVSS: 9.0EPSS: 0%CPEs: 2EXPL: 0

09 Aug 2023 — A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count component, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application. Authenticated users can extract arbitrary information from the DBMS in an uncontrolled way. Una vulnerabilidad de inyección blind SQL en Nozomi Networks Guardian y CMC, debida a una validación de entrada incorrecta en el componente alerts_count, permite a un atacante ... • https://security.nozominetworks.com/NN-2023:3-01 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.8EPSS: 0%CPEs: 2EXPL: 0

09 Aug 2023 — A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application. Authenticated users can extract arbitrary information from the DBMS in an uncontrolled way. Una vulnerabilidad de inyección blind SQL en Guardian y CMC de Nozomi Networks, debido a una validación de entrada incorrecta en el parámetro de ordenación, permite a un atacante au... • https://security.nozominetworks.com/NN-2023:2-01 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 7.0EPSS: 0%CPEs: 2EXPL: 0

09 Aug 2023 — In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session. • https://security.nozominetworks.com/NN-2023:8-01 • CWE-384: Session Fixation •

CVSS: 9.0EPSS: 0%CPEs: 2EXPL: 0

04 May 2023 — Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application. • https://security.nozominetworks.com/NN-2023:1-01 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 8.6EPSS: 0%CPEs: 2EXPL: 0

24 Mar 2022 — Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0. Una vulnerabilidad de comprobación de entrada inapropiada en la carga de archivos de proyectos en Nozomi Networks Guardian y CMC permite a un atac... • https://security.nozominetworks.com/NN-2022:2-02 • CWE-20: Improper Input Validation •

CVSS: 8.6EPSS: 0%CPEs: 2EXPL: 0

24 Mar 2022 — Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0. Una vulnerabilidad de comprobación de entrada inapropiada en la carga de logotipos de informes personalizados en Nozomi Networks Guardian y... • https://security.nozominetworks.com/NN-2022:2-01 • CWE-20: Improper Input Validation •

CVSS: 9.0EPSS: 2%CPEs: 4EXPL: 0

22 Feb 2021 — OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions. Una vulnerabilidad de inyección de comandos del Sistema Operativo cuando se cambia la configuración de fecha o el nombre de host usando la GUI web de Nozomi Net... • https://security.nozominetworks.com/NN-2021:1-01 • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •

CVSS: 8.6EPSS: 0%CPEs: 4EXPL: 0

22 Feb 2021 — Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions. Una vulnerabilidad de Salto de Ruta cuando se cambia la zona horaria usando la GUI web de Nozomi Networks Guardian y CMC, permite a un administrador autenticado tener archivos del sistem... • https://security.nozominetworks.com/NN-2021:2-01 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-24: Path Traversal: '../filedir' •

CVSS: 8.5EPSS: 0%CPEs: 1EXPL: 1

30 Jun 2020 — Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection. El Sistema Operativo Nozomi Networks versiones anteriores a 19.0.4, permite una Inyección CSV de /#/network?tab=network_node_list.html • https://www2.deloitte.com/de/de/pages/risk/articles/nozomi-csv-injection.html?nc=1 • CWE-1236: Improper Neutralization of Formula Elements in a CSV File •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

30 Jun 2020 — Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name. Nozomi Guardian versiones anteriores a 19.0.4, permite a atacantes lograr un ataque de tipo XSS almacenados (en el front end web) al aprovechar la capacidad de crear un campo personalizado con un nombre de campo diseñado • https://www2.deloitte.com/de/de/pages/risk/articles/nozomi-stored-xss.html?nc=1 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •