Back

HIGH

Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0

Published Mar 24, 2022

Description

Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

Affected products

Remediation

Vendor solution

Upgrade to v22.0.0.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Nozomi
Published Mar 24, 2022
Updated Sep 20, 2024
Reserved Feb 9, 2022
CISA Vulnrichment
Updated May 28, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a