Nozomi Networks Guardian and CMC Incorrect Privilege Assignment Vulnerability in Arc Sensors

Vulnerability

A vulnerability allowing incorrect privilege assignment has been identified in Nozomi Networks Guardian and CMC versions prior to 26.2.0. This vulnerability arises from Arc sensors receiving command-line interface (CLI) permissions, which should not be granted. As a result, an authenticated user with limited privileges can exploit this issue by sending administrative CLI commands through the synchronization functionality. This exploitation can lead to unauthorized changes in device configuration and potentially disrupt the device's availability.

Impact

Exploitation of this vulnerability allows authenticated users with limited privileges to execute administrative CLI commands on Arc sensors, modifying device configurations and possibly causing availability issues.

Remediation

Users are advised to upgrade to Nozomi Networks Guardian or CMC version 26.2.0 or later. Additionally, review all enabled Arc sensors and remove or disable any untrusted ones.

Added: Jul 9, 2026, 8:29 AM
Updated: Jul 9, 2026, 8:29 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
5.0
exploitability
4.9
remediation
8.3
relevance
9.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.