PT-2025-24647 · Nozomi Networks · Nozomi Networks Cmc+1

Published

2025-06-10

·

Updated

2025-06-10

·

CVE-2024-13089

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nozomi Networks Guardian and CMC (affected versions not specified)
Description An OS command injection issue exists within the update functionality, potentially allowing authenticated administrators to execute unauthorized arbitrary OS commands. This could impact confidentiality, integrity, and availability, as users with administrative privileges may upload update packages. Although these updates are signed and validated prior to installation, an improper signature validation check has been identified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-13089

Affected Products

Nozomi Networks Cmc
Nozomi Networks Guardian