Nozomi Networks Guardian
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*
- < 26.2.0
A denial-of-service vulnerability has been identified in Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability arises from unbounded resource allocation in the audit logging feature, where excessively large input can be submitted and recorded without any size limit. An unauthenticated attacker could exploit this by sending requests with large inputs, potentially filling up available disk space and causing the system to become inoperable.
Exploitation of this vulnerability can lead to exhaustion of disk space, causing the system to become inoperable.
Users are advised to upgrade to version 26.2.0 or later. Additionally, internal firewall features can be used to limit access to the web management interface.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.