Show filters
38 Total Results
Displaying 1-10 of 38
Sort by:
Attacker Value
Unknown

CVE-2024-3334

Disclosure Date: November 15, 2024 (last updated November 16, 2024)
A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data.
0
Attacker Value
Unknown

CVE-2024-4465

Disclosure Date: September 11, 2024 (last updated September 20, 2024)
An access control vulnerability was discovered in the Reports section due to a specific access restriction not being properly enforced for users with limited privileges. If a logged-in user with reporting privileges learns how to create a specific application request, they might be able to make limited changes to the reporting configuration. This could result in a partial loss of data integrity. In Guardian/CMC instances with a reporting configuration, there could be limited Denial of Service (DoS) impacts, as the reports may not reach their intended destination, and there could also be limited information disclosure impacts. Furthermore, modifying the destination SMTP server for the reports could lead to the compromise of external credentials, as they might be sent to an unauthorized server. This could expand the scope of the attack.
Attacker Value
Unknown

CVE-2024-4225

Disclosure Date: April 30, 2024 (last updated April 30, 2024)
Multiple security vulnerabilities has been discovered in web interface of NetGuardian DIN Remote Telemetry Unit (RTU), by DPS Telecom. Attackers can exploit those security vulnerabilities to perform critical actions such as escalate user's privilege, steal user's credential, Cross Site Scripting (XSS) and Cross-Site Request Forgery (CSRF).
0
Attacker Value
Unknown

CVE-2024-0218

Disclosure Date: April 10, 2024 (last updated May 28, 2024)
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian, caused by improper input validation in certain fields used in the Radius parsing functionality of our IDS, allows an unauthenticated attacker sending specially crafted malformed network packets to cause the IDS module to stop updating nodes, links, and assets. Network traffic may not be analyzed until the IDS module is restarted.
0
Attacker Value
Unknown

CVE-2023-6916

Disclosure Date: April 10, 2024 (last updated May 28, 2024)
Audit records for OpenAPI requests may include sensitive information. This could lead to unauthorized accesses and privilege escalation.
0
Attacker Value
Unknown

CVE-2023-22836

Disclosure Date: January 29, 2024 (last updated February 08, 2024)
In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from the default value, the renamed value may be visible to the rest of the stack’s tenants.
Attacker Value
Unknown

CVE-2023-5253

Disclosure Date: January 15, 2024 (last updated September 20, 2024)
A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication. Malicious unauthenticated users with knowledge on the underlying system may be able to extract limited asset information.
Attacker Value
Unknown

CVE-2023-6253

Disclosure Date: November 22, 2023 (last updated February 14, 2025)
A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file.
Attacker Value
Unknown

CVE-2023-32649

Disclosure Date: September 19, 2023 (last updated May 28, 2024)
A Denial of Service (Dos) vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, allows an unauthenticated attacker to crash the IDS module by sending specially crafted malformed network packets. During the (limited) time window before the IDS module is automatically restarted, network traffic may not be analyzed.
Attacker Value
Unknown

CVE-2023-2567

Disclosure Date: September 19, 2023 (last updated October 01, 2024)
A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality. Authenticated users may be able to execute arbitrary SQL statements on the DBMS used by the web application.