The vendor explicitly identifies these products as affected by this CVE.
- Nozomi Networks Guardian <22.0.0
- Nozomi Networks CMC <22.0.0
- Summary
- Improper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or report manager roles to execute unattended commands on the appliance using web server user privileges.
- Remediation
- Upgrade to v22.0.0.
