Description
A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication.
Malicious unauthenticated users with knowledge on the underlying system may be able to extract limited asset information.
Malicious unauthenticated users with knowledge on the underlying system may be able to extract limited asset information.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to v23.3.0 or later.
Vendor Workaround
Use internal firewall features to limit access to the web management interface.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57578 | A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication. Malicious unauthenticated users with knowledge on the underlying system may be able to extract limited asset information. |
References
| Link | Providers |
|---|---|
| https://security.nozominetworks.com/NN-2023:12-01 |
|
History
Fri, 20 Sep 2024 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication. Malicious unauthenticated users with knowledge on the underlying system may be able to extract asset information. | A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication. Malicious unauthenticated users with knowledge on the underlying system may be able to extract limited asset information. |
Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2025-06-17T21:09:23.231Z
Reserved: 2023-09-28T12:41:27.922Z
Link: CVE-2023-5253
No data.
Status : Modified
Published: 2024-01-15T11:15:08.627
Modified: 2024-11-21T08:41:22.837
Link: CVE-2023-5253
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD