An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XNozominetworks Cmc
APPNozominetworks< 26.2.0Nozominetworks Guardian
APPNozominetworks< 26.2.0
Related vulnerabilities
SQL Injection w Nozomi Networks Guardian i CMC — nieuwierzytelniony dostęp do bazy danych
DoS przez nieograniczoną alokację zasobów w logowaniu audytu — Nozomi Networks
A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper valida...
A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient...
An access control vulnerability was discovered in the CLI functionality due to a specific access restriction n...