Executive brief
Nozomi Networks Guardian and CMC, which are used to monitor and manage industrial control systems, contain a security flaw in how they handle sensor synchronization. An attacker with low-level access to the system can exploit this to issue administrative commands, potentially changing critical device settings or causing a service outage. This could disrupt industrial operations or allow unauthorized changes to the security monitoring infrastructure.
Technical details
An Incorrect Privilege Assignment (CWE-266) exists in the synchronization functionality of Nozomi Networks Guardian and CMC. The vulnerability stems from Arc sensors receiving excessive CLI permissions during the sync process. A network-based attacker with low-privileged credentials can leverage this flaw to push administrative CLI commands to the device. Successful exploitation allows the attacker to modify device configurations or impact system availability. The issue is resolved in version 26.2.0; users are advised to upgrade or review and disable untrusted sensors as a mitigation.
Affected products
- Nozomi Networks Guardian < 26.2.0
- Nozomi Networks CMC < 26.2.0
Timeline
- 2026-07-07: advisory: Initial advisory released by Nozomi Networks
- 2026-07-09: disclosed: CVE published to NVD