Authenticated RCE on logo report upload in Guardian/CMC before 22.0.0
CVE-2022-0550

8.6HIGH

Key Information:

Vendor
CVE Published:
24 March 2022

What is CVE-2022-0550?

Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

Affected Version(s)

CMC < 22.0.0

Guardian < 22.0.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SECURA B.V. found this bug during a scheduled VAPT testing session.
.