Impact
The vulnerability stems from insufficient validation of user privileges in the Credentials Manager. Users with limited authentication rights can view a restricted set of entries, yet they can delete or edit those entries. The actual credential values themselves are not exposed, but manipulation of entry properties can lead to indirect credential compromise or disruption of authentication for devices that rely on those credentials. This elevates a low‑privileged user to a position where they can degrade or compromise system integrity.
Affected Systems
Products impacted are Nozomi Networks CMC and Nozomi Networks Guardian. The advisory covers all versions of these products released before 26.3.0; users of any earlier version are therefore at risk.
Risk and Exploitability
The CVSS base score of 6.4 denotes a moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting the likelihood of exploitation at present may be low. Nonetheless, an attacker who has already authenticated to the web interface—an access that can be gained remotely—could exploit this weakness to delete or alter credentials, potentially disabling authentication for dependent devices or acquiring credentials indirectly. The attack vector is likely remote authenticated access to the web management interface.
OpenCVE Enrichment