VYPR

Cmc

by Nozominetworks

CVEs (43)

  • CVE-2023-24477HigAug 9, 2023
    risk 0.46cvss 7.0epss 0.00

    In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.

  • CVE-2025-40904MedMay 19, 2026
    risk 0.42cvss 6.5epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views…

  • CVE-2023-24471MedAug 9, 2023
    risk 0.42cvss 6.5epss 0.00

    An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functionality. An authenticated user with reduced visibility can obtain unauthorized information via the debug functionality, obtaining…

  • CVE-2023-22843MedAug 9, 2023
    risk 0.42cvss 6.4epss 0.00

    An authenticated attacker with administrative access to the web management interface can inject malicious JavaScript code inside the definition of a Threat Intelligence rule, that will be stored and can later be executed by another legitimate user viewing the details of such a…

  • CVE-2025-40893MedDec 18, 2025
    risk 0.40cvss 6.1epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the…

  • CVE-2024-4465MedSep 11, 2024
    risk 0.39cvss 6.0epss 0.00

    An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with reporting privileges learns how to create a specific application request, they…

  • CVE-2026-31981MedJul 9, 2026
    risk 0.38cvss 5.9epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data…

  • CVE-2025-40903MedMay 19, 2026
    risk 0.38cvss 5.9epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim…

  • CVE-2025-40902MedMay 19, 2026
    risk 0.38cvss 5.9epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete…

  • CVE-2025-40901MedMay 19, 2026
    risk 0.38cvss 5.9epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to…

  • CVE-2026-31983MedJul 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the…

  • CVE-2025-40888MedOct 7, 2025
    risk 0.34cvss 5.3epss 0.00

    A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing…

  • CVE-2025-40887MedOct 7, 2025
    risk 0.34cvss 5.3epss 0.00

    A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing…

  • CVE-2025-40885MedOct 7, 2025
    risk 0.34cvss 5.3epss 0.00

    A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially…

  • CVE-2023-5253MedJan 15, 2024
    risk 0.34cvss 5.3epss 0.00

    A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication. Malicious unauthenticated users with knowledge on the…

  • CVE-2023-23903MedAug 9, 2023
    risk 0.32cvss 4.9epss 0.01

    An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error. The whole application in rendered unusable until a console…

  • CVE-2025-40895MedMar 4, 2026
    risk 0.31cvss 4.8epss 0.00

    A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on connected Guardians' properties. A malicious authenticated user with administrator privileges on a Guardian connected to a CMC can edit the Guardian's…

  • CVE-2025-40891MedDec 18, 2025
    risk 0.31cvss 4.7epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset…

  • CVE-2025-40900MedMay 19, 2026
    risk 0.30cvss 4.6epss 0.00

    An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payload, or a victim can be…

  • CVE-2025-40894MedMar 4, 2026
    risk 0.29cvss 4.4epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation on an input parameter. A malicious authenticated user with the required privileges could edit a node label to inject HTML tags. If the system is…