CVE-2025-40887 PUBLISHED

Authenticated SQL Injection on Alert functionality in Guardian/CMC before 25.2.0

Assigner: Nozomi
Reserved: 16.04.2025 Published: 07.10.2025 Updated: 07.10.2025

A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute arbitrary SELECT SQL statements on the DBMS used by the web application, potentially exposing unauthorized data.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6

Product Status

Vendor Nozomi Networks
Product Guardian
Versions Default: unaffected
  • affected from 0 to 25.2.0 (excl.)
Vendor Nozomi Networks
Product CMC
Versions Default: unaffected
  • affected from 0 to 25.2.0 (excl.)

Workarounds

Review all accounts with access to it and delete unnecessary ones.

Solutions

Upgrade to v25.2.0 or later.

Credits

  • This issue was found by Andrea Palanca of Nozomi Networks Product Security team during an internal investigation. finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-66 SQL Injection