CVE-2021-26725: Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4
Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-26725?
CVE-2021-26725 is a Path Traversal vulnerability in Nozomi Networks Guardian CMC that allows an authenticated administrator to read protected system files.
Which software versions are affected by CVE-2021-26725?
Nozomi Networks Guardian 20.0.7.3 and prior versions, and Nozomi Networks CMC 20.0.7.3 and prior versions are affected by CVE-2021-26725.
How severe is CVE-2021-26725?
CVE-2021-26725 has a severity rating of 4.9 (high).
What is the CWE ID of CVE-2021-26725?
CVE-2021-26725 has CWE IDs 22 and 24.
How can I find more information about CVE-2021-26725?
You can find more information about CVE-2021-26725 on the Nozomi Networks Security Advisory page: https://security.nozominetworks.com/NN-2021:2-01