CVE-2023-2567: Authenticated SQL Injection on Query functionality in Guardian/CMC before 22.6.3 and 23.1.0
A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality. Authenticated users may be able to execute arbitrary SQL statements on the DBMS used by the web application.
Other sources
A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality, allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application. Authenticated users can extract arbitrary information from the DBMS in an uncontrolled way.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2567?
The severity of CVE-2023-2567 is high, with a severity value of 6.5.
Which software is affected by CVE-2023-2567?
Nozomi Networks Guardian and CMC are affected by CVE-2023-2567.
How does CVE-2023-2567 impact affected software?
CVE-2023-2567 allows an authenticated attacker to execute arbitrary SQL queries on the DBMS used by the web application.
What is the fix for CVE-2023-2567?
Please refer to the vendor's security advisory for the fix of CVE-2023-2567.
Are there any references available for CVE-2023-2567?
Yes, you can find more information about CVE-2023-2567 in the vendor's security advisory: [https://security.nozominetworks.com/NN-2023:9-01](https://security.nozominetworks.com/NN-2023:9-01).