<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_nozominetworks/10</id>
  <title>Most recent entries from csaf_nozominetworks</title>
  <updated>2026-10-06T06:36:47.599676+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2019:1-01</id>
    <title>NN-2019:1-01 — Stored XSS in field name data model</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An attacker with admin access to the appliance can inject malicious code that will later be executed by another legitimate users. This allows an attacker to perform unauthorized actions on behalf of legitimate users. JavaScript injection was possible using the field name when adding new column to the data model section. The injected code will then be executed in the environment section under e.g. asset view.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2019:1-01"/>
    <published>2019-11-11T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2019:2-01</id>
    <title>NN-2019:2-01 — CSV Injection on node label</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CSV Injection, also known as Formula Injection, occurs when websites embed untrusted input inside CSV files. An authenticated malicious user can insert a crafted formula in the node label that can be later executed on another system after another user has downloaded and opened the node list export.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2019:2-01"/>
    <published>2019-11-11T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2020:2-01</id>
    <title>NN-2020:2-01 — Cross-site request forgery attack on change password form</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Change password doesn't validate CSRF token properly.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2020:2-01"/>
    <published>2020-05-26T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2020:3-01</id>
    <title>NN-2020:3-01 — Angular template injection on custom report name field</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Report name field is affected by angular template injection which can lead to XSS attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2020:3-01"/>
    <published>2020-05-26T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2021:1-01</id>
    <title>NN-2021:1-01 — Authenticated command injection when changing date settings or hostname in Guardian/CMC before 20.0.7.4</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An OS command injection vulnerability in the management interface allows an authenticated administrator to execute arbitrary OS commands gaining access to the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2021:1-01"/>
    <published>2021-02-22T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2021:2-01</id>
    <title>NN-2021:2-01 — Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An authenticated command path traversal vulnerability in the management interface allows an authenticated administrator to read-protected system files.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2021:2-01"/>
    <published>2021-02-22T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2022:2-01</id>
    <title>NN-2022:2-01 — Authenticated RCE on logo report upload in Guardian/CMC before 22.0.0</title>
    <updated>2024-09-19T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2022:2-01"/>
    <published>2022-02-14T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2022:2-02</id>
    <title>NN-2022:2-02 — Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0</title>
    <updated>2024-09-19T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2022:2-02"/>
    <published>2022-02-14T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2023:1-01</id>
    <title>NN-2023:1-01 — Authenticated SQL Injection on Alerts in Guardian/CMC before 22.5.2</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the Alerts controller, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2023:1-01"/>
    <published>2023-05-03T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2023:2-01</id>
    <title>NN-2023:2-01 — Authenticated Blind SQL Injection on sorting in Guardian/CMC before 22.6.2</title>
    <updated>2024-09-19T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2023:2-01"/>
    <published>2023-08-09T11:00:00+00:00</published>
  </entry>
</feed>
