<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_nozominetworks/10</id>
  <title>Most recent entries from csaf_nozominetworks</title>
  <updated>2026-10-02T11:14:21.758065+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2019:1-01</id>
    <title>NN-2019:1-01 — Stored XSS in field name data model</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An attacker with admin access to the appliance can inject malicious code that will later be executed by another legitimate users. This allows an attacker to perform unauthorized actions on behalf of legitimate users. JavaScript injection was possible using the field name when adding new column to the data model section. The injected code will then be executed in the environment section under e.g. asset view.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2019:1-01"/>
    <published>2019-11-11T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2019:2-01</id>
    <title>NN-2019:2-01 — CSV Injection on node label</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>CSV Injection, also known as Formula Injection, occurs when websites embed untrusted input inside CSV files. An authenticated malicious user can insert a crafted formula in the node label that can be later executed on another system after another user has downloaded and opened the node list export.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2019:2-01"/>
    <published>2019-11-11T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2020:2-01</id>
    <title>NN-2020:2-01 — Cross-site request forgery attack on change password form</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Change password doesn't validate CSRF token properly.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2020:2-01"/>
    <published>2020-05-26T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2020:3-01</id>
    <title>NN-2020:3-01 — Angular template injection on custom report name field</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Report name field is affected by angular template injection which can lead to XSS attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2020:3-01"/>
    <published>2020-05-26T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2021:1-01</id>
    <title>NN-2021:1-01 — Authenticated command injection when changing date settings or hostname in Guardian/CMC before 20.0.7.4</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An OS command injection vulnerability in the management interface allows an authenticated administrator to execute arbitrary OS commands gaining access to the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2021:1-01"/>
    <published>2021-02-22T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2021:2-01</id>
    <title>NN-2021:2-01 — Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An authenticated command path traversal vulnerability in the management interface allows an authenticated administrator to read-protected system files.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2021:2-01"/>
    <published>2021-02-22T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2023:1-01</id>
    <title>NN-2023:1-01 — Authenticated SQL Injection on Alerts in Guardian/CMC before 22.5.2</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the Alerts controller, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2023:1-01"/>
    <published>2023-05-03T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2023:13-01</id>
    <title>NN-2023:13-01 — Missing authentication for local web interface in Arc before v1.6.0</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2023:13-01"/>
    <published>2024-05-15T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2023:14-01</id>
    <title>NN-2023:14-01 — Unsafe temporary data privileges on Unix systems in Arc before v1.6.0</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2023:14-01"/>
    <published>2024-05-15T11:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/nn-2023:16-01</id>
    <title>NN-2023:16-01 — Path traversal via 'zip slip' in Arc before v1.6.0</title>
    <updated>2024-05-20T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/nn-2023:16-01"/>
    <published>2024-05-15T11:00:00+00:00</published>
  </entry>
</feed>
