Nozominetworks

Cmc

41 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 19.05.2026 13:23:35
  • Zuletzt bearbeitet 09.06.2026 10:16:37

A Stored HTML Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input parameter. An authenticated user with limited privileges can push malicious remote strategies containing HTML tags through ...

  • EPSS 0.19%
  • Veröffentlicht 19.05.2026 13:22:15
  • Zuletzt bearbeitet 09.06.2026 10:16:37

A Stored HTML Injection vulnerability was discovered in the Schedule Restore Archive functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious restore schedule containi...

  • EPSS 0.19%
  • Veröffentlicht 19.05.2026 13:21:02
  • Zuletzt bearbeitet 09.06.2026 10:16:37

A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When...

  • EPSS 0.19%
  • Veröffentlicht 19.05.2026 13:19:45
  • Zuletzt bearbeitet 09.06.2026 10:16:36

A Stored HTML Injection vulnerability was discovered in the Credentials Manager functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can define a malicious identity containing HTML tags....

  • EPSS 0.2%
  • Veröffentlicht 19.05.2026 13:17:21
  • Zuletzt bearbeitet 09.06.2026 10:16:36

An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a malicious report containing an Angular template payloa...

  • EPSS 0.29%
  • Veröffentlicht 15.04.2026 08:18:36
  • Zuletzt bearbeitet 12.05.2026 13:17:19

A Stored Cross-Site Scripting vulnerability was discovered in the Assets and Nodes functionality due to improper validation of an input parameter. An authenticated user with custom fields privileges can define a malicious custom field containing a Ja...

  • EPSS 0.33%
  • Veröffentlicht 15.04.2026 08:18:05
  • Zuletzt bearbeitet 12.05.2026 13:17:19

An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restriction not being properly enforced for users with view-only privileges. An authenticated user with view-only privileges for the Thre...

  • EPSS 0.11%
  • Veröffentlicht 04.03.2026 13:52:52
  • Zuletzt bearbeitet 05.03.2026 18:48:12

The server certificate was not verified when an Arc agent connected to a Guardian or CMC. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Arc agent and the Guardian or CMC. This could result i...

  • EPSS 0.18%
  • Veröffentlicht 04.03.2026 13:52:13
  • Zuletzt bearbeitet 05.03.2026 18:50:52

A Stored HTML Injection vulnerability was discovered in the CMC's Sensor Map functionality due to improper validation on connected Guardians' properties. A malicious authenticated user with administrator privileges on a Guardian connected to a CMC...

  • EPSS 0.16%
  • Veröffentlicht 04.03.2026 13:51:14
  • Zuletzt bearbeitet 14.04.2026 10:16:27

A Stored HTML Injection vulnerability was discovered in the Alerted Nodes Dashboard functionality due to improper validation on an input parameter. A malicious authenticated user with the required privileges could edit a node label to inject HTML ...