Executive brief
Nozomi Networks Guardian and CMC appliances, which are used to monitor and manage industrial control systems, contain a security flaw in their archive restoration scheduling feature. An authorized administrator can inject malicious code into a schedule that will execute in the browser of other users who view it. This could be used to perform phishing attacks or redirect users to malicious websites, though existing security controls prevent full data theft or complete system takeover.
Technical details
A Stored HTML Injection vulnerability (CWE-79) exists in the Schedule Restore Archive functionality of Nozomi Networks Guardian and CMC due to improper validation of input parameters. An authenticated attacker with high privileges (administrative access) can define a restore schedule containing malicious HTML tags. When a victim views the schedule, the browser renders the injected HTML. While the vulnerability allows for phishing and open redirects, full Cross-Site Scripting (XSS) and direct information disclosure are mitigated by existing input validation and a restrictive Content Security Policy (CSP). The issue is fixed in version 26.1.0.
Affected products
- Nozomi Networks Guardian < 26.1.0
- Nozomi Networks Central Management Console (CMC) < 26.1.0
Timeline
- 2026-05-19: disclosed: Initial discovery by Nozomi Networks internal security team.
- 2026-05-19: advisory
- 2026-05-19: patched: Fixed in version 26.1.0.