Executive brief
Nozomi Networks Guardian and CMC, which are used for industrial network monitoring and management, are affected by a security vulnerability in their Assets and Nodes management features. An authenticated user with permission to create custom fields can inject malicious scripts that execute when other users view those pages. This could allow an attacker to hijack administrative sessions, modify application data, or disrupt the availability of the monitoring platform.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Assets and Nodes functionality of Nozomi Networks Guardian and CMC due to improper validation of input parameters within custom fields. An authenticated attacker with 'custom fields' privileges can define a field containing a malicious JavaScript payload. When a victim (such as an administrator) views the Assets or Nodes pages, the payload executes in their browser context. This can lead to unauthorized actions performed on behalf of the victim, including data modification, session hijacking, and disruption of application availability. The vulnerability is addressed in Nozomi version 26.0.0 and Siemens RUGGEDCOM APE1808 Nozomi Guardian version 26.2.0.
Affected products
- Nozomi Networks Inc. Guardian < 26.0.0
- Nozomi Networks Inc. Central Management Console (CMC) < 26.0.0
- Siemens RUGGEDCOM APE1808 All versions with Nozomi Guardian/CMC < V26.2.0
Timeline
- 2026-01-13: advisory: Initial Siemens advisory published
- 2026-04-15: disclosed: Initial Nozomi Networks advisory published
- 2026-04-15: patched: Nozomi Networks released version 26.0.0
- 2026-05-12: patched: Siemens released update for RUGGEDCOM APE1808