CVE-2022-4259: Authenticated SQL Injection on Alerts in Guardian/CMC before 22.5.2
Published May 4, 2023
·Updated
Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.
Affected Software
2 affected components
Nozominetworks Cmc<22.5.2
Nozominetworks Guardian<22.5.2
Remediation
Information
Upgrade to version >= 22.5.2
Event History
May 4, 2023
CVE Published
via MITRE·10:38 AM
Data Sourced
via MITRE·10:38 AM
RemedyDescriptionSeverityWeakness
Data Sourced
11:15 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-4259.
2
What is the severity of CVE-2022-4259?
The severity of CVE-2022-4259 is high with a severity value of 8.8.
3
Which software is affected by CVE-2022-4259?
Nozomi Networks Guardian and CMC versions up to 22.5.2 are affected by CVE-2022-4259.
4
What is the impact of the vulnerability?
The vulnerability allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.
5
Is there a fix available for CVE-2022-4259?
Please update Nozomi Networks Guardian and CMC to version 22.5.2 or above to fix CVE-2022-4259.