Impact
An improper certificate/host key validation flaw in the Smart Polling feature allows an attacker who can position themselves between a sensor and a polled device to impersonate the device during a polling session, intercept communication, and capture the credentials used to access the device, which can be replayed to authenticate to the device itself or other devices sharing the same credentials, enabling unauthorized data tampering and operational disruption.
Affected Systems
Nozomi Networks Arc versions earlier than 2.7.0, Nozomi Networks CMC and Guardian versions earlier than 26.3.0 are affected by this vulnerability in the Smart Polling functionality.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate potential impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector requires network control over the path between the sensor and the target device, allowing a man‑in‑the‑middle attacker to intercept the encrypted connection before validation takes place.
OpenCVE Enrichment