Improper Certificate Validation in Smart Polling Feature of Nozomi Networks Products
CVE-2026-33389
5.3MEDIUM
What is CVE-2026-33389?
An improper certificate/host key validation vulnerability has been identified in the Smart Polling functionality of Nozomi Networks products. This flaw enables a man-in-the-middle attacker to intercept communications between a sensor and a target device during polling sessions. By not validating the identity of the remote host, attackers can impersonate devices, potentially capturing credentials used for access. These credentials can then be exploited to gain unauthorized access to not just the compromised device but to any other devices that share the same credentials, leading to potential data tampering and operational disruption.
Affected Version(s)
Arc 0 < 2.7.0
CMC 0 < 26.3.0
Guardian 0 < 26.3.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was found by Stefano Balzarotti of Nozomi Networks and Andrea Palanca of Nozomi Networks Product Security team during an internal investigation.
