Nozomi Networks Guardian and CMC Denial-of-Service Vulnerability via Oversized Audit Log Entries

Vulnerability

A denial-of-service vulnerability has been identified in Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability arises from unbounded resource allocation in the audit logging feature, where excessively large input can be submitted and recorded without any size limit. An unauthenticated attacker could exploit this by sending requests with large inputs, potentially filling up available disk space and causing the system to become inoperable.

Impact

Exploitation of this vulnerability can lead to exhaustion of disk space, causing the system to become inoperable.

Remediation

Users are advised to upgrade to version 26.2.0 or later. Additionally, internal firewall features can be used to limit access to the web management interface.

Added: Jul 9, 2026, 8:31 AM
Updated: Jul 9, 2026, 8:31 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
2.5
exploitability
7.0
remediation
7.9
relevance
9.2
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.