Skip to content

CVE-2023-2567 | Guardian,CMC

A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application. Authenticated users can extract arbitrary information from the DBMS in an uncontrolled way. .This CVE has a CVSS3.1 score of 7.6 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-2567
CVE StatePUBLISHED
BaseScore7.6
BaseSeverityHIGH
VectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
VersionNA

References for CVE-2023-2567 :
https://security.nozominetworks.com/NN-2023:9-01

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)LOW
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)HIGH
Availability(A)LOW
Integrity(I)LOW