<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_nozominetworks/10</id>
  <title>Most recent entries from csaf_nozominetworks</title>
  <updated>2026-10-02T10:11:19.191622+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2026:20-01</id>
    <title>NN-2026:20-01 — Disabled and non-configurable certificate/host key validation in Smart Polling in Guardian/CMC before 26.3.0 and Arc be…</title>
    <updated>2026-09-08T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2026:20-01"/>
    <published>2026-09-08T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2026:19-01</id>
    <title>NN-2026:19-01 — Incorrect authorization in Credentials Manager in Guardian/CMC before 26.3.0</title>
    <updated>2026-09-08T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2026:19-01"/>
    <published>2026-09-08T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2026:18-01</id>
    <title>NN-2026:18-01 — Cross-site request forgery in the Guardian/CMC login before 26.3.0</title>
    <updated>2026-09-08T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A cross-site request forgery vulnerability was discovered in the login functionality (both standard and SAML) due to missing validation of the anti-CSRF token.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2026:18-01"/>
    <published>2026-09-08T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2026:17-01</id>
    <title>NN-2026:17-01 — Incorrect authorization in Smart Polling configuration in Guardian/CMC before 26.3.0</title>
    <updated>2026-09-08T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient validation of user privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2026:17-01"/>
    <published>2026-09-08T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2026:16-01</id>
    <title>NN-2026:16-01 — Insufficient sanitization of Dashboards in Guardian/CMC before 26.3.0</title>
    <updated>2026-09-08T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2026:16-01"/>
    <published>2026-09-08T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2026:15-01</id>
    <title>NN-2026:15-01 — Path traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0</title>
    <updated>2026-08-11T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2026:15-01"/>
    <published>2026-08-11T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2026:14-01</id>
    <title>NN-2026:14-01 — Npcap driver installed without administrator-only access restriction on Windows in Arc before v2.7.0</title>
    <updated>2026-08-11T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2026:14-01"/>
    <published>2026-08-11T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2026:9-01</id>
    <title>NN-2026:9-01 — Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0</title>
    <updated>2026-07-07T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2026:9-01"/>
    <published>2026-07-07T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2026:8-01</id>
    <title>NN-2026:8-01 — HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0</title>
    <updated>2026-07-07T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2026:8-01"/>
    <published>2026-07-07T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2026:13-01</id>
    <title>NN-2026:13-01 — Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0</title>
    <updated>2026-07-07T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2026:13-01"/>
    <published>2026-07-07T11:00:00+00:00</published>
  </entry>
</feed>
