Nozomi Networks Guardian
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*
- < 26.2.0
A vulnerability allowing open redirection has been identified in the SAML Single Sign-On feature of Nozomi Networks Guardian and CMC applications, prior to version 26.2.0. This vulnerability arises from inadequate validation of user-controlled redirection parameters. An unauthenticated attacker could exploit this by sending a crafted request to the SAML sign-in endpoint, which would then corrupt the cached SAML redirection for other users. As a result, this could facilitate phishing and credential theft, while also disrupting SAML authentication for all impacted users.
Exploitation of this vulnerability allows for open redirection, which could be used in phishing attacks to steal credentials from users.
Users are advised to upgrade to version 26.2.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.