Description
Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.
Published: 2023-05-04
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Upgrade to version >= 22.5.2


Vendor Workaround

Use internal firewall features to limit access to the web management interface.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-51615 Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.
History

No history.

Subscriptions

Nozominetworks Cmc Guardian
cve-icon MITRE

Status: PUBLISHED

Assigner: Nozomi

Published:

Updated: 2024-08-03T01:34:49.836Z

Reserved: 2022-12-01T16:10:50.593Z

Link: CVE-2022-4259

cve-icon Vulnrichment

Updated: 2024-08-03T01:34:49.836Z

cve-icon NVD

Status : Modified

Published: 2023-05-04T11:15:08.930

Modified: 2024-11-21T07:34:53.517

Link: CVE-2022-4259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses