HIGH🇵🇱 Wersja polska

CVE-2026-33390

CVSS 7.2v4.0pub. 2026-07-09upd. 2026-08-11

An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Nozominetworks Cmc

    APP
    Nozominetworks
    < 26.2.0
  • Nozominetworks Guardian

    APP
    Nozominetworks
    < 26.2.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-29245CRITICAL9.2PL ✓same product

SQL Injection w Nozomi Networks Guardian i CMC — nieuwierzytelniony dostęp do bazy danych

CVE-2026-31984HIGH8.7PL ✓same product

DoS przez nieograniczoną alokację zasobów w logowaniu audytu — Nozomi Networks

CVE-2025-40892HIGH7.1same product

A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper valida...

CVE-2025-40898HIGH7.2same product

A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient...

CVE-2025-3719HIGH7.2same product

An access control vulnerability was discovered in the CLI functionality due to a specific access restriction n...