VendorsNozomi Networksguardianany version
Vulnerabilities

Nozomi Networks Guardian any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

41CVEs
CVE-2023-29245
SQL Injection on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0
Published 2023-09-19 · Modified
9.2EPSS 0.006
CVE-2021-26724
Authenticated command injection when changing date settings or hostname in Guardian/CMC before 20.0.7.4
Published 2021-02-22 · Modified
9.0EPSS 0.028
CVE-2025-40892
Stored Cross-Site Scripting (XSS) in Reports in Guardian/CMC before 25.5.0
Published 2025-12-18 · Modified
8.9EPSS 0.003
CVE-2023-2567
Authenticated SQL Injection on Query functionality in Guardian/CMC before 22.6.3 and 23.1.0
Published 2023-09-19 · Analyzed
8.8EPSS 0.006
CVE-2023-22378
Authenticated Blind SQL Injection on sorting in Guardian/CMC before 22.6.2
Published 2023-08-09 · Modified
8.8EPSS 0.006
CVE-2023-23574
Authenticated Blind SQL Injection on alerts count in Guardian/CMC before 22.6.2
Published 2023-08-09 · Analyzed
8.8EPSS 0.006
CVE-2022-4259
Authenticated SQL Injection on Alerts in Guardian/CMC before 22.5.2
Published 2023-05-04 · Modified
8.8EPSS 0.006
CVE-2025-40886
Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0
Published 2025-10-07 · Analyzed
8.8EPSS 0.003
CVE-2026-31984
DoS through oversized audit log entries in Guardian/CMC before 26.2.0
Published 2026-07-09 · Modified
8.7EPSS 0.005
CVE-2021-26725
Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4
Published 2021-02-22 · Modified
8.6EPSS 0.011
CVE-2022-0550
Authenticated RCE on logo report upload in Guardian/CMC before 22.0.0
Published 2022-03-24 · Modified
8.6EPSS 0.009
CVE-2022-0551
Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0
Published 2022-03-24 · Modified
8.6EPSS 0.009
CVE-2020-7049
Nozomi Networks OS before 19.0.4 allows /#/network?tab=network_node_list.html CSV Injection.
Published 2020-06-30 · Modified
8.5EPSS 0.009
CVE-2023-32649
DoS on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0
Published 2023-09-19 · Modified
8.2EPSS 0.006
CVE-2025-40889
Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0
Published 2025-10-07 · Analyzed
8.1EPSS 0.004
CVE-2025-40898
Path traversal in Import Arc data archive functionality in Guardian/CMC before 25.5.0
Published 2025-12-18 · Modified
8.1EPSS 0.004
CVE-2026-33390
Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0
Published 2026-07-09 · Modified
8.1EPSS 0.004
CVE-2025-3719
Incorrect authorization for CLI in Guardian/CMC before 25.2.0
Published 2025-10-07 · Analyzed
8.1EPSS 0.003
CVE-2025-3718
Client-side path traversal in Guardian/CMC before 25.2.0
Published 2025-10-07 · Analyzed
7.9EPSS 0.002
CVE-2023-5253
Check Point IoT integration: WebSocket returns assets data without authentication in Guardian/CMC before 23.3.0
Published 2024-01-15 · Modified
7.5EPSS 0.005
CVE-2023-22843
Stored Cross-Site Scripting (XSS) in Threat Intelligence rules in Guardian/CMC before 22.6.2
Published 2023-08-09 · Modified
7.3EPSS 0.003
CVE-2023-24471
Information disclosure via the debug function in assertions in Guardian/CMC before 22.6.2
Published 2023-08-09 · Modified
7.1EPSS 0.005
CVE-2026-31982
Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0
Published 2026-07-09 · Modified
7.1EPSS 0.003
CVE-2023-24477
Session Fixation in Guardian/CMC before 22.6.2
Published 2023-08-09 · Modified
7.0EPSS 0.001
CVE-2023-23903
DoS via SAML configuration in Guardian/CMC before 22.6.2
Published 2023-08-09 · Modified
6.9EPSS 0.006
CVE-2026-31983
Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0
Published 2026-07-09 · Modified
6.9EPSS 0.004
CVE-2025-40885
Authenticated SQL Injection on Smart Polling functionality in Guardian/CMC before 25.2.0
Published 2025-10-07 · Analyzed
6.5EPSS 0.002
CVE-2025-40887
Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0
Published 2025-10-07 · Analyzed
6.5EPSS 0.002
CVE-2025-40888
Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0
Published 2025-10-07 · Analyzed
6.5EPSS 0.002
CVE-2025-40904
HTML injection in Smart Polling in Guardian/CMC before 26.1.0
Published 2026-05-19 · Modified
6.5EPSS 0.002
CVE-2020-15307
Nozomi Guardian before 19.0.4 allows attackers to achieve stored XSS (in the web front end) by leveraging the ability to create a custom field with a crafted field name.
Published 2020-06-30 · Modified
6.1EPSS 0.007
CVE-2025-40893
HTML injection in Asset List in Guardian/CMC before 25.5.0
Published 2025-12-18 · Modified
6.1EPSS 0.002
CVE-2024-4465
Incorrect authorization for Reports configuration in Guardian/CMC before 24.2.0
Published 2024-09-11 · Modified
6.0EPSS 0.002
CVE-2026-31981
HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0
Published 2026-07-09 · Modified
5.9EPSS 0.003
CVE-2025-40901
HTML injection in Credentials Manager in Guardian/CMC before 26.1.0
Published 2026-05-19 · Modified
5.9EPSS 0.002
CVE-2025-40902
HTML injection in Users in Guardian/CMC before 26.1.0
Published 2026-05-19 · Modified
5.9EPSS 0.002
CVE-2025-40903
HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0
Published 2026-05-19 · Modified
5.9EPSS 0.002
CVE-2025-40894
HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0
Published 2026-03-04 · Modified
5.4EPSS 0.002
CVE-2023-24015
Partial DoS on Reports section due to null report name in Guardian/CMC before 22.6.2
Published 2023-08-09 · Modified
5.3EPSS 0.005
CVE-2025-40900
Angular template injection in Reports in Guardian/CMC before 26.1.0
Published 2026-05-19 · Modified
5.1EPSS 0.002
1 / 2Next →