CVE-2025-40890

7.9

Nozomi Networks · Guardian and CMC

A stored cross-site scripting vulnerability in Nozomi Networks Guardian and CMC dashboard functionality allows authenticated attackers to execute arbitrary JavaScript in the context of other users.

Executive summary

An authenticated stored cross-site scripting vulnerability in Nozomi Networks Guardian and CMC allows attackers to perform unauthorized actions as other users, posing a significant risk to system integrity.

Vulnerability

This vulnerability is a stored cross-site scripting (CWE-79) flaw located within the dashboard functionality. It requires an authenticated low-privilege user to craft and share a malicious dashboard or trick a victim into importing a malicious template, which then executes in the victim's browser.

Business impact

The ability for an attacker to execute arbitrary scripts in the context of other users, including administrators, can lead to the unauthorized modification of application data and disruption of service. Given the CVSS score of 7.9, this vulnerability presents a high risk to operational continuity and data security, as successful exploitation could allow an attacker to bypass access controls or perform actions on behalf of privileged personnel.

Remediation

Immediate Action: Upgrade Nozomi Networks Guardian and CMC installations to version 25.4.0 or later to apply the necessary input validation fixes.

Proactive Monitoring: Monitor user activity logs for suspicious dashboard imports or unusual modifications to shared dashboard configurations.

Compensating Controls: Implement strict Content Security Policy (CSP) headers on the web interface to restrict the execution of unauthorized scripts and utilize a Web Application Firewall to filter malicious payloads in dashboard inputs.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Nozomi Networks Guardian or CMC should prioritize upgrading to version 25.4.0 immediately. Due to the potential for privilege escalation via XSS against administrative accounts, applying this patch is essential to maintain the security posture of the industrial control system management environment.

More Nozomi Networks CVEs

Sources

Originally found and disclosed by This issue was found by Humza Ahmad of ENCS during a VAPT testing session commissioned by one of our customers., per the CVE Program record.