Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.
History

Fri, 20 Sep 2024 11:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nozominetworks:cmc:22.0.0:*:*:*:*:*:*:*
cpe:2.3:a:nozominetworks:guardian:22.0.0:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Sep 2024 10:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published: 2022-03-24T14:15:22

Updated: 2024-09-20T10:34:31.686Z

Reserved: 2022-02-09T00:00:00

Link: CVE-2022-0551

cve-icon Vulnrichment

Updated: 2024-08-02T23:32:46.290Z

cve-icon NVD

Status : Modified

Published: 2022-03-24T15:15:07.917

Modified: 2024-11-21T06:38:53.827

Link: CVE-2022-0551

cve-icon Redhat

No data.