NN-2020:3-01

Angular template injection on custom report name field

Last update: 2020-05-26

Advisory IDNN-2020:3-01
TopicAngular template injection on custom report name field
ImpactXSS
Issue date2020-05-26
AffectsN2OS <v20.0.3, Guardian and CMC
CVE Name(s)NA
CVSS Score4.8
CVE Risk LevelMedium
Risk Level for Nozomi customersLow

Summary

Report name field is affected by angular template injection which can lead to XSS attacks.

Impact

Custom report name field can lead to XSS attacks by malicious users. The attacker must have a valid Guardian/CMC login with the ‘Report editor’ capability to leverage this.

Affected Products

Guardian / CMC before v20.0.3.

Workarounds and Mitigations

None

Solutions

v19 series: Upgrade to v19.0.11 v20 series: Upgrade to v20.0.3

Modification History

2020-05-26: Initial revision

Related Links

None

Acknowledgements

This bug was found by Schneider Electric Industry Services

Contact

Nozomi Networks Product Security team can be reached at prodsec@nozominetworks.com. More contact details on the PSIRT page.