Nozomi Networks Remote Collector TLS Certificate Validation Vulnerability

Vulnerability

A vulnerability exists in Nozomi Networks Remote Collector versions prior to 26.2.0, where the n2os-tui interface disables TLS certificate verification when connecting to an upstream Guardian or CMC. This lack of validation, combined with the absence of an option to re-enable it, exposes users to potential man-in-the-middle attacks. Such attacks could intercept communications, steal sync tokens, impersonate servers, inject false asset information or vulnerabilities into the Guardian or CMC, and disrupt data flow between the Remote Collector and these services.

Impact

Exploitation of this vulnerability could lead to a man-in-the-middle attack, allowing interception of communications between the Remote Collector and the Guardian or CMC. This could result in theft of the sync token, server impersonation, injection of spoofed data into the Guardian or CMC, or disruption of the data flow between the Remote Collector and the Guardian or CMC.

Remediation

Users can manually edit the 'n2os.conf.user' file in the Remote Collector to enable TLS certificate verification by removing the '!' prefix from the upstream Guardian or CMC endpoint entry. Alternatively, upgrading the Remote Collector to version 26.2.0 or later will also address this vulnerability.

Added: Jul 9, 2026, 8:29 AM
Updated: Jul 9, 2026, 8:29 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.2
remediation
0.0
relevance
9.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.