VYPR

Guardian

by Nozominetworks

CVEs (44)

  • CVE-2021-26724HigFeb 22, 2021
    risk 0.47cvss 7.2epss 0.03

    OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior…

  • CVE-2026-31982HigJul 9, 2026
    risk 0.46cvss 7.1epss 0.00

    An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection…

  • CVE-2023-24477HigAug 9, 2023
    risk 0.46cvss 7.0epss 0.00

    In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout. Thus an authenticated local attacker may gain acces to the original user's session.

  • CVE-2025-40904MedMay 19, 2026
    risk 0.42cvss 6.5epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through the sync. When a victim views…

  • CVE-2023-24471MedAug 9, 2023
    risk 0.42cvss 6.5epss 0.00

    An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functionality. An authenticated user with reduced visibility can obtain unauthorized information via the debug functionality, obtaining…

  • CVE-2023-22843MedAug 9, 2023
    risk 0.42cvss 6.4epss 0.00

    An authenticated attacker with administrative access to the web management interface can inject malicious JavaScript code inside the definition of a Threat Intelligence rule, that will be stored and can later be executed by another legitimate user viewing the details of such a…

  • CVE-2025-40893MedDec 18, 2025
    risk 0.40cvss 6.1epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Asset List functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets to inject HTML tags into asset attributes. When a victim views the…

  • CVE-2020-15307MedJun 30, 2020
    risk 0.40cvss 6.1epss 0.01

    Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.

  • CVE-2024-4465MedSep 11, 2024
    risk 0.39cvss 6.0epss 0.00

    An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with reporting privileges learns how to create a specific application request, they…

  • CVE-2026-31981MedJul 9, 2026
    risk 0.38cvss 5.9epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated user with administrative privileges can inject malicious HTML tags into N2OS configuration data…

  • CVE-2025-40903MedMay 19, 2026
    risk 0.38cvss 5.9epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containing HTML tags. When a victim…

  • CVE-2025-40902MedMay 19, 2026
    risk 0.38cvss 5.9epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete…

  • CVE-2025-40901MedMay 19, 2026
    risk 0.38cvss 5.9epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags. When a victim attempts to…

  • CVE-2026-31983MedJul 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpoint and obtain the list of users that have uploaded their public SSH keys, their groups, and the…

  • CVE-2025-40888MedOct 7, 2025
    risk 0.34cvss 5.3epss 0.00

    A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing…

  • CVE-2025-40887MedOct 7, 2025
    risk 0.34cvss 5.3epss 0.00

    A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing…

  • CVE-2025-40885MedOct 7, 2025
    risk 0.34cvss 5.3epss 0.00

    A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially…

  • CVE-2023-5253MedJan 15, 2024
    risk 0.34cvss 5.3epss 0.00

    A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication. Malicious unauthenticated users with knowledge on the…

  • CVE-2023-23903MedAug 9, 2023
    risk 0.32cvss 4.9epss 0.01

    An authenticated administrator can upload a SAML configuration file with the wrong format, with the application not checking the correct file format. Every subsequent application request will return an error. The whole application in rendered unusable until a console…

  • CVE-2025-40891MedDec 18, 2025
    risk 0.31cvss 4.7epss 0.00

    A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset…