Impact
An incorrect privilege assignment flaw allows Arc sensors to receive command‑line interface permissions that should only be granted to administrators. An authenticated user with limited privileges can use the synchronization feature to push administrative CLI commands, thereby altering device configuration and potentially disrupting availability. The flaw is a CWE‑266 weakness, where proper privilege levels are not enforced.
Affected Systems
The vulnerability affects Nozomi Networks CMC and Guardian products prior to version 26.2.0. Any deployment of these products that has not been upgraded is susceptible.
Risk and Exploitability
The CVSS score is 7.2, indicating a high severity. EPSS is under 1%, implying low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication and the presence of a user with limited privileges who can access the synchronization functionality; the attacker can then inject administrative CLI commands through that channel.
OpenCVE Enrichment