<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Nozomi Networks security portal RSS Feed]]></title><description><![CDATA[Nozomi Networks incident response portal contains security bulletins about Nozomi Networks products.]]></description><link>https://security.nozominetworks.com</link><generator>NozomiNetworksRSS</generator><lastBuildDate>Thu, 16 Apr 2026 08:35:44 GMT</lastBuildDate><item><title><![CDATA[NN-2026:1-01]]></title><description><![CDATA[Incorrect authorization for Threat Intelligence in Guardian/CMC before 26.0.0]]></description><link>https://security.nozominetworks.com/NN-2026:1-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2026:1-01</guid><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2026:2-01]]></title><description><![CDATA[Stored Cross-Site Scripting (XSS) in Assets and Nodes in Guardian/CMC before 26.0.0]]></description><link>https://security.nozominetworks.com/NN-2026:2-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2026:2-01</guid><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:16-01]]></title><description><![CDATA[HTML injection in Alerted Nodes Dashboard in Guardian/CMC before 25.6.0]]></description><link>https://security.nozominetworks.com/NN-2025:16-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:16-01</guid><pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:17-01]]></title><description><![CDATA[HTML injection in Sensor Map in CMC before 25.6.0]]></description><link>https://security.nozominetworks.com/NN-2025:17-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:17-01</guid><pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:18-01]]></title><description><![CDATA[Lack of TLS certificate validation when connecting Arc to a Guardian or CMC, in Arc before v2.2.0]]></description><link>https://security.nozominetworks.com/NN-2025:18-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:18-01</guid><pubDate>Wed, 04 Mar 2026 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:12-01]]></title><description><![CDATA[HTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0]]></description><link>https://security.nozominetworks.com/NN-2025:12-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:12-01</guid><pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:13-01]]></title><description><![CDATA[Stored Cross-Site Scripting (XSS) in Reports in Guardian/CMC before 25.5.0]]></description><link>https://security.nozominetworks.com/NN-2025:13-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:13-01</guid><pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:14-01]]></title><description><![CDATA[HTML injection in Asset List in Guardian/CMC before 25.5.0]]></description><link>https://security.nozominetworks.com/NN-2025:14-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:14-01</guid><pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:15-01]]></title><description><![CDATA[Path traversal in Import Arc data archive functionality in Guardian/CMC before 25.5.0]]></description><link>https://security.nozominetworks.com/NN-2025:15-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:15-01</guid><pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:11-01]]></title><description><![CDATA[Stored Cross-Site Scripting (XSS) in Dashboards in Guardian/CMC before 25.4.0]]></description><link>https://security.nozominetworks.com/NN-2025:11-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:11-01</guid><pubDate>Wed, 26 Nov 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:10-01]]></title><description><![CDATA[Authenticated SQL Injection on CLI functionality in Guardian/CMC before 25.3.0]]></description><link>https://security.nozominetworks.com/NN-2025:10-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:10-01</guid><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:4-01]]></title><description><![CDATA[Client-side path traversal in Guardian/CMC before 25.2.0]]></description><link>https://security.nozominetworks.com/NN-2025:4-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:4-01</guid><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:5-01]]></title><description><![CDATA[Incorrect authorization for CLI in Guardian/CMC before 25.2.0]]></description><link>https://security.nozominetworks.com/NN-2025:5-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:5-01</guid><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:6-01]]></title><description><![CDATA[Authenticated SQL Injection on Smart Polling functionality in Guardian/CMC before 25.2.0]]></description><link>https://security.nozominetworks.com/NN-2025:6-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:6-01</guid><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:7-01]]></title><description><![CDATA[Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0]]></description><link>https://security.nozominetworks.com/NN-2025:7-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:7-01</guid><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:8-01]]></title><description><![CDATA[Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0]]></description><link>https://security.nozominetworks.com/NN-2025:8-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:8-01</guid><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:9-01]]></title><description><![CDATA[Path traversal in Time Machine functionality in Guardian/CMC before 25.2.0]]></description><link>https://security.nozominetworks.com/NN-2025:9-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:9-01</guid><pubDate>Tue, 07 Oct 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:3-01]]></title><description><![CDATA[Incorrect authorization for traces request/download in CMC before 25.1.0]]></description><link>https://security.nozominetworks.com/NN-2025:3-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:3-01</guid><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:1-01]]></title><description><![CDATA[Authenticated RCE in update functionality in Guardian/CMC before 24.6.0]]></description><link>https://security.nozominetworks.com/NN-2025:1-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:1-01</guid><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2025:2-01]]></title><description><![CDATA[Privilege escalation in Guardian/CMC before 24.6.0]]></description><link>https://security.nozominetworks.com/NN-2025:2-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2025:2-01</guid><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2022:2-01]]></title><description><![CDATA[Authenticated RCE on logo report upload in Guardian/CMC before 22.0.0]]></description><link>https://security.nozominetworks.com/NN-2022:2-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2022:2-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2022:2-02]]></title><description><![CDATA[Authenticated RCE on project configuration import in Guardian/CMC before 22.0.0]]></description><link>https://security.nozominetworks.com/NN-2022:2-02</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2022:2-02</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:10-01]]></title><description><![CDATA[DoS on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0]]></description><link>https://security.nozominetworks.com/NN-2023:10-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:10-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:11-01]]></title><description><![CDATA[SQL Injection on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0]]></description><link>https://security.nozominetworks.com/NN-2023:11-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:11-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:12-01]]></title><description><![CDATA[Check Point IoT integration: WebSocket returns assets data without authentication in Guardian/CMC before 23.3.0]]></description><link>https://security.nozominetworks.com/NN-2023:12-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:12-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:15-01]]></title><description><![CDATA[Sensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0]]></description><link>https://security.nozominetworks.com/NN-2023:15-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:15-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:17-01]]></title><description><![CDATA[Information disclosure via audit records for OpenAPI requests in Guardian/CMC before 23.4.1]]></description><link>https://security.nozominetworks.com/NN-2023:17-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:17-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:2-01]]></title><description><![CDATA[Authenticated Blind SQL Injection on sorting in Guardian/CMC before 22.6.2]]></description><link>https://security.nozominetworks.com/NN-2023:2-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:2-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:3-01]]></title><description><![CDATA[Authenticated Blind SQL Injection on alerts count in Guardian/CMC before 22.6.2]]></description><link>https://security.nozominetworks.com/NN-2023:3-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:3-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:4-01]]></title><description><![CDATA[Stored Cross-Site Scripting (XSS) in Threat Intelligence rules in Guardian/CMC before 22.6.2]]></description><link>https://security.nozominetworks.com/NN-2023:4-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:4-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:6-01]]></title><description><![CDATA[Partial DoS on Reports section due to null report name in Guardian/CMC before 22.6.2]]></description><link>https://security.nozominetworks.com/NN-2023:6-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:6-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:7-01]]></title><description><![CDATA[DoS via SAML configuration in Guardian/CMC before 22.6.2]]></description><link>https://security.nozominetworks.com/NN-2023:7-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:7-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:8-01]]></title><description><![CDATA[Session Fixation in Guardian/CMC before 22.6.2]]></description><link>https://security.nozominetworks.com/NN-2023:8-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:8-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:9-01]]></title><description><![CDATA[Authenticated SQL Injection on Query functionality in Guardian/CMC before 22.6.3 and 23.1.0]]></description><link>https://security.nozominetworks.com/NN-2023:9-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:9-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2024:1-01]]></title><description><![CDATA[DoS on IDS parsing of malformed Radius packets in Guardian before 23.4.1]]></description><link>https://security.nozominetworks.com/NN-2024:1-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2024:1-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2024:2-01]]></title><description><![CDATA[Incorrect authorization for Reports configuration in Guardian/CMC before 24.2.0]]></description><link>https://security.nozominetworks.com/NN-2024:2-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2024:2-01</guid><pubDate>Thu, 19 Sep 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2019:1-01]]></title><description><![CDATA[Stored XSS in field name data model]]></description><link>https://security.nozominetworks.com/NN-2019:1-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2019:1-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2019:2-01]]></title><description><![CDATA[CSV Injection on node label]]></description><link>https://security.nozominetworks.com/NN-2019:2-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2019:2-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2020:1-01]]></title><description><![CDATA[NGINX allows HTTP request smuggling]]></description><link>https://security.nozominetworks.com/NN-2020:1-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2020:1-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2020:2-01]]></title><description><![CDATA[Cross-site request forgery attack on change password form]]></description><link>https://security.nozominetworks.com/NN-2020:2-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2020:2-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2020:3-01]]></title><description><![CDATA[Angular template injection on custom report name field]]></description><link>https://security.nozominetworks.com/NN-2020:3-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2020:3-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2021:1-01]]></title><description><![CDATA[Authenticated command injection when changing date settings or hostname in Guardian/CMC before 20.0.7.4]]></description><link>https://security.nozominetworks.com/NN-2021:1-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2021:1-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2021:2-01]]></title><description><![CDATA[Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4]]></description><link>https://security.nozominetworks.com/NN-2021:2-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2021:2-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:1-01]]></title><description><![CDATA[Authenticated SQL Injection on Alerts in Guardian/CMC before 22.5.2]]></description><link>https://security.nozominetworks.com/NN-2023:1-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:1-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:13-01]]></title><description><![CDATA[Missing authentication for local web interface in Arc before v1.6.0]]></description><link>https://security.nozominetworks.com/NN-2023:13-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:13-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:14-01]]></title><description><![CDATA[Unsafe temporary data privileges on Unix systems in Arc before v1.6.0]]></description><link>https://security.nozominetworks.com/NN-2023:14-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:14-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:16-01]]></title><description><![CDATA[Path traversal via 'zip slip' in Arc before v1.6.0]]></description><link>https://security.nozominetworks.com/NN-2023:16-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:16-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item><item><title><![CDATA[NN-2023:5-01]]></title><description><![CDATA[Information disclosure via the debug function in assertions in Guardian/CMC before 22.6.2]]></description><link>https://security.nozominetworks.com/NN-2023:5-01</link><guid isPermaLink="false">https://security.nozominetworks.com/NN-2023:5-01</guid><pubDate>Mon, 20 May 2024 00:00:00 GMT</pubDate></item></channel></rss>