CVE-2022-0551

HIGH

Nozomi Networks <22.0.0 - Code Injection

Title source: llm
STIX 2.1

Description

Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://security.nozominetworks.com/NN-2022:2-02

Scores

CVSS v3 7.2
EPSS 0.0087
EPSS Percentile 54.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
nozominetworks/cmc < 22.0.0
nozominetworks/guardian < 22.0.0
Published Mar 24, 2022
Tracked Since Feb 18, 2026