Impact
An authenticated user with limited privileges can bypass intended access control of the web management interface and modify Smart Polling discovery configuration. This flaw results from insufficient validation of user permissions and is classified as CWE-863. The attacker can remotely alter settings that govern how the system discovers devices, thereby causing the monitoring platform to miss assets and reducing the overall integrity and availability of network visibility.
Affected Systems
The vulnerability affects Nozomi Networks CMC and Guardian devices running any version prior to v26.3.0. All users of these products should verify whether their firmware or software is below that revision and consider upgrading if still in use.
Risk and Exploitability
The CVSS v3 score of 5.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA's KEV catalog, suggesting limited known exploitation. The likely attack vector is a remote authenticated compromise via the web interface. An attacker with limited account privileges can execute the exploit and disrupt asset discovery, but would need valid credentials and network access to the management portal.
OpenCVE Enrichment