Improper Certificate Validation in Smart Polling Feature of Nozomi Networks Products
CVE-2026-33389

5.3MEDIUM

Key Information:

Vendor
CVE Published:
8 September 2026

What is CVE-2026-33389?

An improper certificate/host key validation vulnerability has been identified in the Smart Polling functionality of Nozomi Networks products. This flaw enables a man-in-the-middle attacker to intercept communications between a sensor and a target device during polling sessions. By not validating the identity of the remote host, attackers can impersonate devices, potentially capturing credentials used for access. These credentials can then be exploited to gain unauthorized access to not just the compromised device but to any other devices that share the same credentials, leading to potential data tampering and operational disruption.

Affected Version(s)

Arc 0 < 2.7.0

CMC 0 < 26.3.0

Guardian 0 < 26.3.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was found by Stefano Balzarotti of Nozomi Networks and Andrea Palanca of Nozomi Networks Product Security team during an internal investigation.
.