Executive brief
A denial-of-service vulnerability exists in Nozomi Networks Guardian and CMC, which are used for industrial network monitoring and management. An attacker can send specially crafted requests that fill up the system's storage with oversized log entries. This can cause the device to run out of disk space, leading to a complete system crash or making the management interface unavailable.
Technical details
A denial-of-service vulnerability (CWE-770) exists in the audit logging functionality of Nozomi Networks Guardian and CMC. The root cause is a failure to enforce size limits on input data before it is recorded into audit log entries. A remote, unauthenticated attacker can exploit this by submitting network requests containing excessively large payloads. These payloads are written to disk as part of the audit trail, eventually exhausting available disk space. This resource exhaustion renders the system inoperable. The vulnerability is resolved in version 26.2.0.
Affected products
- Nozomi Networks Guardian < 26.2.0
- Nozomi Networks CMC < 26.2.0
Timeline
- 2026-07-07: advisory: Initial internal advisory revision
- 2026-07-09: disclosed: NVD publication date