Impact
The vulnerability is a template injection flaw in the Dashboards feature of Nozomi Networks CMC and Guardian. An authenticated user with sufficient privileges can craft a dashboard that contains malicious code, or an attacker can convince a victim to import a malicious dashboard. When viewed or imported, the payload runs in the victim’s browser context, permitting the attacker to alter application data or cause availability disruptions. The flaw is classified as CWE‑1336.
Affected Systems
Nozomi Networks CMC and Nozomi Networks Guardian devices running versions prior to 26.3.0 are affected. Any system that allows users to create or import dashboards through the web management interface is vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS information is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely known exploitation yet. The attack vector is the web interface; successful exploitation requires an authenticated user with dashboard creation privileges or a socially engineered victim who imports a malicious dashboard. The impact is limited to the victim browser session, but it can lead to data tampering or service disruption within the application.
OpenCVE Enrichment