← Vulnerability feed

Vulnerability record · CVE-2022-0551 · published 24 March 2022

CVE-2022-0551: Nozominetworks cmc improper input validation vulnerability

Nozominetworks · Cmc

Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

8.6 CVSS 4.0 High EPSS 0.90% · top 41.8% CWE-20 · Improper input validation
8.6CVSS 4.0 base score, v2 6.5
0.90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Improper Input Validation vulnerability in project file upload in Nozomi Networks Guardian and CMC allows an authenticated attacker with admin or import manager roles to execute unattended commands on the appliance using web server user privileges. This issue affects: Nozomi Networks Guardian versions prior to 22.0.0. Nozomi Networks CMC versions prior to 22.0.0.

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0551 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2023-29245Nozominetworks cmc sql injection vulnerabilityA SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence …EPSS 0.61%8.7CVE-2026-31984Nozominetworks cmc allocation without limits vulnerabilityA denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size li…EPSS 0.51%8.7CVE-2023-2567Nozominetworks cmc sql injection vulnerabilityA SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the …EPSS 0.62%8.7CVE-2023-22378Nozominetworks cmc sql injection vulnerabilityA blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the sorting parameter, allows an authent…EPSS 0.61%8.7CVE-2023-23574Nozominetworks cmc sql injection vulnerabilityA blind SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in the alerts_count component, allows an au…EPSS 0.61%8.7CVE-2022-4259Nozominetworks cmc sql injection vulnerabilityDue to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated …EPSS 0.60%8.6CVE-2022-0550Nozominetworks cmc improper input validation vulnerabilityImproper Input Validation vulnerability in custom report logo upload in Nozomi Networks Guardian, and CMC allows an authenticated attacker with admin…EPSS 0.90%8.6CVE-2021-26724Nozominetworks central management control os command injection vulnerabilityOS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated adm…EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2022-0551), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.