CVE-2025-40892

8.9

Nozomi Networks · Guardian and CMC

A stored cross-site scripting vulnerability in the Reports functionality of Nozomi Networks Guardian and CMC allows authenticated users to execute malicious JavaScript in a victim's browser.

Executive summary

A stored cross-site scripting vulnerability in Nozomi Networks Guardian and CMC allows authenticated attackers to execute unauthorized actions, posing a significant risk to application integrity.

Vulnerability

This vulnerability is a stored cross-site scripting flaw (CWE-79) triggered by improper input validation within the reports module. An authenticated user with report privileges can inject malicious payloads that execute when a victim views or imports a compromised report.

Business impact

The exploitation of this vulnerability allows an attacker to perform actions on behalf of the victim, potentially leading to unauthorized modification of application data or disruption of service. Given the CVSS score of 8.9, this is classified as a high-severity issue that could compromise the integrity and availability of critical operational technology management systems.

Remediation

Immediate Action: Upgrade both Nozomi Networks Guardian and CMC installations to version 25.5.0 or later to resolve the underlying input validation deficiency.

Proactive Monitoring: Security teams should monitor system access logs for anomalous report generation patterns or unusual URL parameters associated with the reports functionality.

Compensating Controls: Deploy a Web Application Firewall (WAF) with strict cross-site scripting filtering rules to intercept and block malicious payloads directed at the report management endpoints.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Due to the high CVSS severity and the potential for lateral movement or data corruption within the management interface, organizations must prioritize the application of the 25.5.0 update. Administrators should verify the integrity of existing report templates and restrict report-creation privileges to trusted personnel until the patch is fully deployed.

More Nozomi Networks CVEs

Sources

Originally found and disclosed by This issue was found by Stefano Libero of Nozomi Networks Product Security team during an internal investigation., per the CVE Program record.