CVE-2022-4259
04.05.2023, 11:15
Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nozominetworks | cmc | 𝑥 < 22.5.2 |
| nozominetworks | guardian | 𝑥 < 22.5.2 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| nozominetworks | cmc | 𝑥 < 22.5.2 | ADP |
| nozominetworks | guardian | 𝑥 < 22.5.2 | ADP |