Impact
A cross‑site request forgery flaw exists in the standard and SAML login flows of Nozomi Networks CMC and Guardian. The missing anti‑CSRF token allows an attacker who already has a valid account to cause a logged‑in victim to unknowingly authenticate under the attacker’s credentials. As a result, every action performed by the victim while logged in is recorded as coming from the attacker’s account, undermining the integrity of audit logs. This is a CWE-352 vulnerability.
Affected Systems
The vulnerability affects Nozomi Networks CMC and Guardian products before version 26.3.0. Users running any prior release should be notified and applied the update as soon as possible.
Risk and Exploitability
The CVSS score of 5.1 suggests moderate severity. EPSS data is not available, and the issue is not listed in the CISA KEV catalog, indicating no publicly known exploitation at the time of this analysis. The attack requires the victim to be logged in with a valid user account and to be directed to a crafted request. Based on the description, it is inferred that the likely attack vector involves a malicious link or embedded form. Because the attacker does not need to bypass authentication, the exploit is feasible in a social engineering scenario, but the lack of a publicly disclosed exploit reduces immediate threat probability.
OpenCVE Enrichment