Impact
A user‑controlled redirect parameter in the SAML Single Sign‑On process is insufficiently validated, allowing an attacker to craft a request to the sign‑in endpoint that changes the cached redirect for other users. This open redirect can lure users to phishing sites, steal their credentials, or disrupt legitimate SAML authentication for all affected devices.
Affected Systems
Nozomi Networks CMC and Guardian devices running versions prior to 26.2.0 are affected.
Risk and Exploitability
The vulnerability can be triggered by unauthenticated attackers through the public SAML sign‑in interface, making it an application‑layer attack that does not require privileged credentials. Its CVSS score of 5.3 indicates moderate severity, while an EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The issue is not listed in the CISA KEV catalog. The likely attack vector is via the web interface that processes the SAML sign‑in request.
OpenCVE Enrichment