CVE-2025-40899

8.9

Nozomi Networks · Guardian and CMC

A stored cross-site scripting vulnerability in Nozomi Networks Guardian and CMC allows authenticated users with custom field privileges to execute malicious JavaScript in a victim's browser context.

Executive summary

An authenticated stored cross-site scripting vulnerability in Nozomi Networks Guardian and CMC versions prior to 26.0.0 poses a risk of unauthorized actions and data manipulation.

Vulnerability

This is a stored cross-site scripting (CWE-79) vulnerability occurring within the Assets and Nodes functionality. An attacker requires authenticated access with custom fields privileges to inject malicious JavaScript payloads that execute when a victim views the affected pages.

Business impact

The vulnerability carries a CVSS score of 8.9, indicating a high level of severity due to the potential for significant impact on data integrity and application availability. Successful exploitation allows an attacker to perform actions on behalf of the victim, which could lead to the modification of sensitive application data, disruption of critical services, and unauthorized access to information.

Remediation

Immediate Action: Upgrade both Nozomi Networks Guardian and CMC instances to version 26.0.0 or later as provided by the vendor.

Proactive Monitoring: Review administrative access logs for suspicious activity involving custom field creation or modifications to Assets and Nodes.

Compensating Controls: Implement a strict Content Security Policy (CSP) to restrict the execution of unauthorized scripts and utilize a Web Application Firewall (WAF) to inspect input parameters for malicious JavaScript patterns.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for high impact on system integrity and the availability of a vendor-supplied patch, organizations should prioritize the update to version 26.0.0. Testing and deployment of this update should be performed according to standard change management procedures to ensure the continued stability of monitoring operations.

More Nozomi Networks CVEs

Sources

Originally found and disclosed by This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation., per the CVE Program record.