Junglewise Threat Intelligence

CVE-2025-40897: Nozomi Networks Guardian and CMC incorrect authorization in Threat Intelligence

CVE-2025-40897 · Severity: high · CVSS 8.1 · Published 2026-04-15

Technologies: Nozomi Networks Guardian, Siemens Ruggedcom Ape1808, Nozomi Networks Central Management Console. Vendors: Nozomi Networks, Siemens.

Executive brief

Nozomi Networks Guardian and CMC are industrial cybersecurity platforms used to monitor and protect critical infrastructure networks. A security flaw in the Threat Intelligence module allows users who should only have 'view-only' access to perform administrative tasks. This means a low-privileged user could modify security rules or disable threat detection features, potentially leaving the industrial environment unprotected against cyber threats.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the Threat Intelligence component of Nozomi Networks Guardian and CMC. The application fails to properly enforce access restrictions for users assigned view-only permissions. An authenticated attacker with these limited privileges can bypass intended restrictions to perform administrative actions, such as altering rule configurations or impacting the availability of threat intelligence services. The vulnerability is reachable over the network without user interaction. Nozomi Networks has released version 26.0.0 to address this issue, while Siemens recommends upgrading RUGGEDCOM APE1808 deployments to version 26.2.0.

Affected products

  • Nozomi Networks Guardian < 26.0.0
  • Nozomi Networks Central Management Console (CMC) < 26.0.0
  • Siemens RUGGEDCOM APE1808 (Nozomi Guardian/CMC) < 26.2.0

Timeline

  • 2026-01-13: advisory: Initial Siemens advisory publication
  • 2026-04-15: disclosed: Nozomi Networks advisory published
  • 2026-04-15: patched: Nozomi Networks released version 26.0.0
  • 2026-05-12: other: Siemens advisory updated

References

Related threats