Description
An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS commands. Users with administrative privileges may upload update packages to upgrade the versions of Nozomi Networks Guardian and CMC. While these updates are signed and their signatures are validated prior to installation, an improper signature validation check has been identified. This issue could potentially enable users to execute commands remotely on the appliance, thereby impacting confidentiality, integrity, and availability.
References (1)
Core 1
Core References
Various Sources
https://security.nozominetworks.com/NN-2025:1-01
Scores
CVSS v3
7.2
EPSS
0.0099
EPSS Percentile
58.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (2)
Nozomi Networks/CMC
< 24.6.0
Nozomi Networks/Guardian
< 24.6.0
Published
Jun 10, 2025
Tracked Since
Feb 18, 2026