The vendor explicitly identifies these products as affected by this CVE.
- Nozomi Networks Arc <1.6.0
- Summary
- When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself.
- Remediation
- Upgrade to v1.6.0 or later.
