Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.
References
Link Resource
https://security.nozominetworks.com/NN-2022:2-01 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Nozomi

Published: 2022-03-24T14:15:20

Updated: 2024-05-28T10:34:04.028Z

Reserved: 2022-02-09T00:00:00


Link: CVE-2022-0550

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-03-24T15:15:07.853

Modified: 2024-05-28T11:15:09.800


Link: CVE-2022-0550

JSON object: View

cve-icon Redhat Information

No data.

CWE