CVE-2023-29245: SQL Injection on IDS parsing of malformed asset fields in Guardian/CMC >= 22.6.0 before 22.6.3 and 23.1.0
A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application by sending specially crafted malicious network packets.
Malicious users with extensive knowledge on the underlying system may be able to extract arbitrary information from the DBMS in an uncontrolled way, alter its structure and data, and/or affect its availability.
Other sources
A SQL Injection vulnerability in Nozomi Networks Guardian and CMC, due to improper input validation in certain fields used in the Asset Intelligence functionality of our IDS, may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application by sending specially crafted malicious network packets.
Malicious users with extensive knowledge on the underlying system may be able to extract arbitrary information from the DBMS in an uncontrolled way, or to alter its structure and data.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-29245?
CVE-2023-29245 is a SQL Injection vulnerability in Nozomi Networks Guardian and CMC due to improper input validation in certain fields used in the Asset Intelligence functionality of the IDS, which may allow an unauthenticated attacker to execute arbitrary SQL statements on the DBMS used by the web application.
How does CVE-2023-29245 impact Nozomi Networks Guardian and CMC?
CVE-2023-29245 impacts Nozomi Networks Guardian and CMC by potentially allowing an unauthenticated attacker to execute arbitrary SQL statements on the database management system (DBMS) used by the web application.
What is the severity of CVE-2023-29245?
CVE-2023-29245 has a severity rating of 7.4 (high).
How can I fix CVE-2023-29245?
To fix CVE-2023-29245, it is recommended to update Nozomi Networks Guardian and CMC to versions 22.6.3 or later, or versions 23.1.0 or later, which include proper input validation to mitigate the SQL Injection vulnerability.
Where can I find more information about CVE-2023-29245?
You can find more information about CVE-2023-29245 on the Nozomi Networks security website at the following link: [https://security.nozominetworks.com/NN-2023:11-01](https://security.nozominetworks.com/NN-2023:11-01)