The vendor explicitly identifies these products as affected by this CVE.
- RUGGEDCOM APE1808 with Nozomi Guardian/CMC< V26.2.0
- Summary
- An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated attacker can craft a request to the SAML sign-in endpoint and poison the cached SAML redirection for other users who subsequently initiate SAML Single Sign-On, enabling phishing and credential-theft attacks, as well as disrupting SAML authentication for all affected users.
- Remediation
- Upgrade Nozomi Guardian to v26.2.0. Contact customer support to receive patch and update information
