Executive brief
Nozomi Networks Remote Collector, a tool used to gather data from industrial networks, contains a flaw where it fails to verify the security certificates of the central management servers it connects to. This allows a malicious actor positioned on the network to intercept or tamper with the data being sent between systems. An attacker could use this to steal authentication tokens, provide false information about network vulnerabilities, or disrupt monitoring operations.
Technical details
A vulnerability exists in the Nozomi Networks Remote Collector where the n2os-tui configuration utility generates configurations that explicitly disable TLS certificate verification (CWE-671). This occurs when connecting the Remote Collector to an upstream Guardian or Central Management Console (CMC). A network-positioned attacker can perform a man-in-the-middle (MitM) attack to intercept communications, steal synchronization tokens, or inject spoofed asset and vulnerability data. The issue is resolved in version 26.2.0; a manual workaround involves editing the 'n2os.conf.user' file to remove the '!' prefix from the upstream endpoint entry.
Affected products
- Nozomi Networks Remote Collector before v26.2.0
Timeline
- 2026-07-07: advisory: Initial internal advisory published by Nozomi Networks
- 2026-07-09: disclosed: CVE published to NVD