Description
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.
No analysis available yet.
Remediation
Vendor Solution
v19 series: Upgrade to v19.0.12. v20 series: Upgrade to v20.0.7.4.
Vendor Workaround
Use internal firewall feature to limit management interface access and review user roles.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-13511 | OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions. |
References
| Link | Providers |
|---|---|
| https://security.nozominetworks.com/NN-2021:1-01 |
|
History
No history.
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2024-09-17T04:05:00.334Z
Reserved: 2021-02-05T00:00:00.000Z
Link: CVE-2021-26724
No data.
Status : Modified
Published: 2021-02-22T21:15:19.787
Modified: 2024-11-21T05:56:45.173
Link: CVE-2021-26724
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD