Impact
A stored HTML injection flaw exists in the Diagram tab and Graph view of Nozomi Networks’ CMC and Guardian products when running any release earlier than 26.2.0. An authenticated user with administrative privileges can insert malicious HTML tags into N2OS configuration data through multiple input vectors. When another user views the affected data in the diagram or graph view, the injected HTML renders in their browser. This rendering can be used to conduct phishing or open‑redirect attacks, even though full cross‑site scripting exploitation and direct information disclosure are mitigated by existing input validation and Content‑Security‑Policy settings.
Affected Systems
Nozomi Networks’ CMC and Guardian products are vulnerable in any release prior to 26.2.0. The vulnerability affects installations that expose the diagram and graph interfaces to web users.
Risk and Exploitability
The CVSS score of 4.8 places this issue in the medium severity range, and the EPSS score of less than 1% suggests that exploit attempts will be rare. The vulnerability is not listed in the CISA KEV catalog. Attacker must first obtain authenticated administrative access to inject the payload; the subsequent rendering requires a user to view the data. Because the flaw is bounded by current CSP controls, the risk to confidentiality, integrity, and availability is modest, but cosmetic and phishing implications can still be significant for exposed web interfaces.
OpenCVE Enrichment