Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-51615 Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.
Fixes

Solution

Upgrade to version >= 22.5.2


Workaround

Use internal firewall features to limit access to the web management interface.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2024-08-03T01:34:49.836Z

Reserved: 2022-12-01T16:10:50.593Z

Link: CVE-2022-4259

cve-icon Vulnrichment

Updated: 2024-08-03T01:34:49.836Z

cve-icon NVD

Status : Modified

Published: 2023-05-04T11:15:08.930

Modified: 2024-11-21T07:34:53.517

Link: CVE-2022-4259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.