<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_nozominetworks</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:11:19 +0000</lastBuildDate>
    <item>
      <title>NN-2019:1-01 — Stored XSS in field name data model</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2019:1-01</link>
      <description>&lt;p&gt;An attacker with admin access to the appliance can inject malicious code that will later be executed by another legitimate users. This allows an attacker to perform unauthorized actions on behalf of legitimate users. JavaScript injection was possible using the field name when adding new column to the data model section. The injected code will then be executed in the environment section under e.g. asset view.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An attacker with admin access to the appliance can inject malicious code that will later be executed by another legitimate users. This allows an attacker to perform unauthorized actions on behalf of legitimate users. JavaScript injection was possible using the field name when adding new column to the data model section. The injected code will then be executed in the environment section under e.g. asset view.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2019:1-01</guid>
      <pubDate>Mon, 11 Nov 2019 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2019:2-01 — CSV Injection on node label</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2019:2-01</link>
      <description>&lt;p&gt;CSV Injection, also known as Formula Injection, occurs when websites embed untrusted input inside CSV files. An authenticated malicious user can insert a crafted formula in the node label that can be later executed on another system after another user has downloaded and opened the node list export.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CSV Injection, also known as Formula Injection, occurs when websites embed untrusted input inside CSV files. An authenticated malicious user can insert a crafted formula in the node label that can be later executed on another system after another user has downloaded and opened the node list export.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2019:2-01</guid>
      <pubDate>Mon, 11 Nov 2019 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2020:2-01 — Cross-site request forgery attack on change password form</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2020:2-01</link>
      <description>&lt;p&gt;Change password doesn&amp;#39;t validate CSRF token properly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Change password doesn&amp;#39;t validate CSRF token properly.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2020:2-01</guid>
      <pubDate>Tue, 26 May 2020 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2020:3-01 — Angular template injection on custom report name field</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2020:3-01</link>
      <description>&lt;p&gt;Report name field is affected by angular template injection which can lead to XSS attacks.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Report name field is affected by angular template injection which can lead to XSS attacks.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2020:3-01</guid>
      <pubDate>Tue, 26 May 2020 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2021:1-01 — Authenticated command injection when changing date settings or hostname in Guardian/CMC before 20.0.7.4</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2021:1-01</link>
      <description>&lt;p&gt;An OS command injection vulnerability in the management interface allows an authenticated administrator to execute arbitrary OS commands gaining access to the system.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An OS command injection vulnerability in the management interface allows an authenticated administrator to execute arbitrary OS commands gaining access to the system.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2021:1-01</guid>
      <pubDate>Mon, 22 Feb 2021 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2021:2-01 — Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2021:2-01</link>
      <description>&lt;p&gt;An authenticated command path traversal vulnerability in the management interface allows an authenticated administrator to read-protected system files.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An authenticated command path traversal vulnerability in the management interface allows an authenticated administrator to read-protected system files.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2021:2-01</guid>
      <pubDate>Mon, 22 Feb 2021 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2022:2-01 — Authenticated RCE on logo report upload in Guardian/CMC before 22.0.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2022:2-01</link>
      <description>&lt;p&gt;Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2022:2-01</guid>
      <pubDate>Mon, 14 Feb 2022 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2022:2-02 — Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2022:2-02</link>
      <description>&lt;p&gt;Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2022:2-02</guid>
      <pubDate>Mon, 14 Feb 2022 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2023:1-01 — Authenticated SQL Injection on Alerts in Guardian/CMC before 22.5.2</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2023:1-01</link>
      <description>&lt;p&gt;A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the Alerts controller, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the Alerts controller, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2023:1-01</guid>
      <pubDate>Wed, 03 May 2023 11:00:00 +0000</pubDate>
    </item>
    <item>
      <title>NN-2023:2-01 — Authenticated Blind SQL Injection on sorting in Guardian/CMC before 22.6.2</title>
      <link>https://cve.radiocsirt.org/vuln/nn-2023:2-01</link>
      <description>&lt;p&gt;A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/nn-2023:2-01</guid>
      <pubDate>Wed, 09 Aug 2023 11:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
