📦 Cmc

by Nozominetworks

🔍 What is Cmc?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-40892

HIGH CVSS 8.9 Dec 18, 2025

A stored XSS vulnerability in the Reports functionality allows authenticated users with report privileges to inject malicious JavaScript into reports. When victims view or import these reports, the at...

CVE-2025-40898

HIGH CVSS 8.1 Dec 18, 2025

This path traversal vulnerability allows authenticated users with limited privileges to upload malicious Arc data archives that can write arbitrary files to any location on the system. This could lead...

CVE-2025-40889

HIGH CVSS 8.1 Oct 7, 2025

An authenticated path traversal vulnerability in Time Machine functionality allows limited-privilege users to manipulate files in the /data folder through specially crafted requests. This affects syst...

CVE-2025-40886

HIGH CVSS 7.5 Oct 7, 2025

This SQL injection vulnerability in the Alert functionality allows authenticated users with limited privileges to execute arbitrary SQL commands on the database. This could lead to unauthorized data a...

CVE-2025-3719

HIGH CVSS 8.1 Oct 7, 2025

An access control vulnerability in CLI functionality allows authenticated users with limited privileges to execute administrative commands. This enables unauthorized configuration changes and potentia...

CVE-2023-32649

HIGH CVSS 7.5 Sep 19, 2023

An unauthenticated attacker can cause a denial of service in Nozomi Networks Guardian and CMC by sending specially crafted malformed packets to the Asset Intelligence functionality. This crashes the I...

CVE-2023-29245

HIGH CVSS 8.1 Sep 19, 2023

An unauthenticated SQL injection vulnerability in Nozomi Networks Guardian and CMC allows attackers to execute arbitrary SQL commands via specially crafted network packets targeting the Asset Intellig...

CVE-2023-23574

HIGH CVSS 8.8 Aug 9, 2023

This is a blind SQL injection vulnerability in Nozomi Networks Guardian and CMC products that allows authenticated attackers to execute arbitrary SQL statements on the underlying database. Attackers c...

CVE-2023-22378

HIGH CVSS 8.8 Aug 9, 2023

This CVE describes a blind SQL injection vulnerability in Nozomi Networks Guardian and CMC products. Authenticated attackers can execute arbitrary SQL statements due to improper input validation in th...

CVE-2023-24477

HIGH CVSS 7.0 Aug 9, 2023

This vulnerability allows an authenticated local attacker to potentially access another user's session after logout in Guardian/CMC software. The issue occurs under specific timing conditions when usi...

CVE-2022-4259

HIGH CVSS 8.8 May 4, 2023

This SQL injection vulnerability in Nozomi Networks Guardian and CMC allows authenticated attackers to execute arbitrary SQL queries on the underlying database. Attackers could potentially read, modif...

CVE-2022-0550

HIGH CVSS 7.2 Mar 24, 2022

This vulnerability allows authenticated attackers with admin or report manager roles to execute arbitrary commands on Nozomi Networks Guardian and CMC appliances through improper input validation in c...

CVE-2025-40895

MEDIUM CVSS 4.8 Mar 4, 2026

A stored HTML injection vulnerability in CMC's Sensor Map allows authenticated administrators on connected Guardian devices to inject malicious HTML into Guardian properties. When CMC users interact w...

CVE-2025-40891

MEDIUM CVSS 4.7 Dec 18, 2025

A stored HTML injection vulnerability in Time Machine Snapshot Diff functionality allows unauthenticated attackers to inject HTML tags into asset attributes across two snapshots. When victims use the ...

CVE-2025-40893

MEDIUM CVSS 6.1 Dec 18, 2025

An unauthenticated attacker can inject HTML into asset attributes by sending crafted network packets to the Asset List functionality. When users view affected assets, the injected HTML renders in thei...

CVE-2025-40885

MEDIUM CVSS 5.3 Oct 7, 2025

A SQL injection vulnerability in the Smart Polling functionality allows authenticated users with limited privileges to execute arbitrary SELECT SQL statements. This could expose unauthorized data from...

CVE-2025-40888

MEDIUM CVSS 5.3 Oct 7, 2025

An authenticated SQL injection vulnerability in CLI functionality allows limited-privilege users to execute arbitrary SELECT statements against the database. This exposes sensitive data that should be...