Junglewise Threat Intelligence

CVE-2026-33389: Nozomi Networks Guardian/CMC and Arc improper certificate validation in Smart Polling

CVE-2026-33389 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Nozomi Networks Guardian, Nozomi Networks Central Management Console. Vendors: Nozomi Networks.

Executive brief

Nozomi Networks Guardian, CMC, and Arc are industrial monitoring and management platforms used to supervise and control critical infrastructure devices. The Smart Polling feature establishes encrypted connections to monitored devices but fails to validate the remote device's identity, allowing an attacker positioned on the network between the sensor and a polled device to intercept credentials and access or disrupt the monitored systems.

Technical details

The vulnerability is an improper certificate/host key validation issue (CWE-671: Lack of Administrator Control over Security) in the Smart Polling functionality. During encrypted polling sessions, the affected products do not validate the remote host's certificate or identity, and no configuration option exists to enable validation. A man-in-the-middle attacker on the network path between a sensor and a polled device can impersonate the target device, intercept encrypted traffic, and capture authentication credentials transmitted during polling. The captured credentials can be replayed to gain unauthorized access to the polled device or other systems sharing the same credentials. The vulnerability requires network proximity and active attack during a polling session; patches are available in Guardian/CMC v26.3.0 and Arc v2.7.0 and later.

Affected products

  • Nozomi Networks Guardian before 26.3.0
  • Nozomi Networks CMC before 26.3.0
  • Nozomi Networks Arc before 2.7.0

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: patched: Patches released: Guardian/CMC v26.3.0 and Arc v2.7.0

References

Related threats