By vendor

Nozominetworks vulnerabilities

Known CVEs affecting Nozominetworks products, prioritized by severity, with SEC.co remediation and detection guidance.

5 published vulnerabilities

  • CVE-2026-33390HIGH 8.1

    A privilege escalation vulnerability exists in Nozomi Networks devices where the synchronization feature incorrectly grants administrative command-line interface (CLI) permissions to Arc sensors. An authenticated user with limited privileges can exploit this to push administrative commands through the sync mechanism, potentially reconfiguring devices or disrupting their operation. The vulnerability requires an attacker to be already authenticated to the system, but does not require any user interaction to trigger.

  • CVE-2026-31984HIGH 7.5

    A denial-of-service vulnerability exists in the audit logging functionality of Nozomi Networks products that allows unauthenticated attackers to submit oversized requests. These requests are recorded into audit entries without size restrictions, causing unbounded disk consumption that can render the system inoperable. An attacker needs only network access and no credentials to trigger this condition.

  • CVE-2026-31982HIGH 7.1

    A flaw in the SAML single sign-on mechanism allows an unauthenticated attacker to redirect users to a malicious website during the authentication process. By poisoning the cached redirection target, an attacker can trick multiple users into entering their credentials on a fake login page or disrupt their ability to authenticate altogether. The vulnerability requires user interaction—specifically, the user must initiate the SAML sign-on flow—but no prior authentication is needed to set up the attack.

  • CVE-2026-31981MEDIUM 5.9

    A stored HTML injection vulnerability in Nozomi Networks CMC and Guardian allows authenticated administrators to inject malicious HTML into configuration data. When other users view the affected data in the Diagram tab or Graph view, the injected HTML renders in their browsers. This can be used to conduct phishing attacks or redirect users to malicious sites. The vulnerability requires administrative access to exploit and user interaction (viewing the affected data) to trigger, limiting its scope but still warranting remediation in environments where admin accounts may be compromised or insider threats are a concern.

  • CVE-2026-31983MEDIUM 5.3

    CVE-2026-31983 is a missing authentication vulnerability in the SSH keys synchronization endpoint of Nozomi Networks products. An attacker without credentials can query this endpoint to retrieve sensitive information: a complete list of users who have uploaded SSH keys, their group memberships, and the actual public SSH keys themselves. This is a straightforward authentication bypass that exposes information an attacker would typically need valid credentials to access.