CVE-2022-0550

HIGH

Nozomi Networks Guardian <22.0.0 - RCE

Title source: llm
STIX 2.1

Description

Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.nozominetworks.com/NN-2022:2-01

Scores

CVSS v3 7.2
EPSS 0.0087
EPSS Percentile 54.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (2)
nozominetworks/cmc < 22.0.0
nozominetworks/guardian < 22.0.0
Published Mar 24, 2022
Tracked Since Feb 18, 2026