PT-2024-5072 · Nozomi · Nozomi Guardian+1

Maciej Kosz

·

Published

2024-04-10

·

Updated

2024-09-20

·

CVE-2023-6916

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Nozomi Guardian and Nozomi Central Management Console (CMC) (affected versions not specified) OpenAPI (affected versions not specified)
Description: The issue is related to insufficient protection of audit records for OpenAPI requests, which may include sensitive information. This could lead to unauthorized accesses and privilege escalation.
Recommendations: For Nozomi Guardian and Nozomi Central Management Console (CMC), consider restricting access to audit records to minimize the risk of exploitation. For OpenAPI, as a temporary workaround, consider disabling the logging of sensitive information in audit records until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-05599
CVE-2023-6916

Affected Products

Nozomi Central Management Console
Nozomi Guardian