Executive brief
A security vulnerability exists in Nozomi Networks Guardian and CMC appliances, which are used to monitor and manage industrial control systems. An attacker can manipulate the login process to redirect legitimate users to malicious websites or disrupt their ability to log in entirely. This could be used to steal employee credentials or prevent administrators from accessing the management console during an incident.
Technical details
An open redirect vulnerability (CWE-601) exists in the SAML Single Sign-On (SSO) implementation of Nozomi Networks Guardian and CMC. The flaw stems from insufficient validation of a user-controlled redirection parameter at the SAML sign-in endpoint. An unauthenticated remote attacker can craft a malicious request that poisons the cached SAML redirection for subsequent users. Successful exploitation allows an attacker to redirect users to arbitrary external domains to facilitate phishing or credential theft, and can also be used to disrupt the authentication flow for all users. The issue is resolved in version 26.2.0.
Affected products
- Nozomi Networks Guardian < 26.2.0
- Nozomi Networks CMC < 26.2.0
Timeline
- 2026-07-07: advisory: Initial vendor advisory released
- 2026-07-09: disclosed: NVD publication date