VYPR

Guardian and CMC

by Nozominetworks

CVEs (7)

  • CVE-2023-23574HigAug 9, 2023
    risk 0.57cvss 8.8epss 0.01

    A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count component, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application. Authenticated users may be able…

  • CVE-2024-4465MedSep 11, 2024
    risk 0.39cvss 6.0epss 0.00

    An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with reporting privileges learns how to create a specific application request, they…

  • CVE-2026-33390Jul 9, 2026
    risk 0.00cvss epss 0.00

    An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device…

  • CVE-2026-31984Jul 9, 2026
    risk 0.00cvss epss 0.00

    A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker can submit requests containing excessively large input that…

  • CVE-2026-31983Jul 9, 2026
    risk 0.00cvss epss 0.00

    A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the…

  • CVE-2026-31982Jul 9, 2026
    risk 0.00cvss epss 0.00

    An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection…

  • CVE-2026-31981Jul 9, 2026
    risk 0.00cvss epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data…