CVE-2025-40886

7.5

Nozomi Networks · Guardian and CMC

A SQL injection vulnerability in the Alert functionality of Nozomi Networks Guardian and CMC allows authenticated users to execute arbitrary SQL commands on the underlying database.

Executive summary

An authenticated SQL injection vulnerability in Nozomi Networks Guardian and CMC poses a significant risk of unauthorized data exposure and potential system compromise.

Vulnerability

The vulnerability is a SQL injection flaw (CWE-89) within the Alert functionality, triggered by improper validation of input parameters. An authenticated user with limited privileges can exploit this to execute arbitrary SQL statements against the backend database.

Business impact

Successful exploitation allows an attacker to bypass standard application logic, leading to the unauthorized disclosure, modification, or deletion of sensitive data stored within the database. Given the CVSS score of 7.5, this high-severity flaw could lead to complete loss of data confidentiality and integrity, potentially disrupting critical monitoring operations provided by the affected systems.

Remediation

Immediate Action: Upgrade Nozomi Networks Guardian and CMC to version 25.2.0 or later to apply the necessary input validation patches.

Proactive Monitoring: Review database access logs for anomalous query patterns, particularly those originating from the Alert functionality or associated service accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with updated rulesets to detect and block common SQL injection patterns targeting the application endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Nozomi Networks Guardian or CMC should prioritize updating to version 25.2.0. By addressing this SQL injection flaw, administrators effectively eliminate the risk of database-level compromise that could otherwise lead to unauthorized data access or service degradation.

More Nozomi Networks CVEs

Sources

Originally found and disclosed by This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation., per the CVE Program record.