Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nozominetworks

First CVE: Jun 30, 2020Active for: 6 yearsTotal CVEs: 45
29.9
VTI Score
Low

Nozominetworks develops network visibility and operational-technology security products, including the Guardian and Central Management Control platforms, that are deployed across critical-infrastructure and industrial environments to monitor and defend networked systems. The vendor's vulnerability footprint, though narrow in product scope, ranks among more prominent vendors in the landscape due to the security-critical role these appliances play in monitoring and controlling operational networks. Vulnerabilities affecting the vendor recur consistently through application-layer input-handling weakness classes: cross-site scripting, SQL injection, path traversal, and improper input validation are the durable signals across its product line, reflecting the web-interface and API-driven architecture of network management appliances. Defenders should treat this vendor's advisories as high-priority for any deployed Guardian or Central Management Control instance, since these products sit between operators and their critical infrastructure; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
45
Total CVEs
More Total CVEs than 98% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 78% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nozominetworks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 30, 2020
6 years ago
Most Recent CVE
Jul 9, 2026
19 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33390HIGH
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited
Jul 9, 20268.134NONO
CVE-2026-31984HIGH
A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audi
Jul 9, 20267.533NONO
CVE-2026-31982HIGH
An Open Redirect vulnerability was discovered in the SAML Single Sign-On functionality due to insufficient validation of a user-controlled redirection parameter. An unauthenticated
Jul 9, 20267.132NONO
CVE-2025-40892HIGH
A Stored Cross-Site Scripting vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileg
Dec 18, 20258.928NONO
CVE-2025-40886HIGH
A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter. An authenticated user with limited privileges can execute
Oct 7, 20258.828NONO
CVE-2022-4259HIGH
Due to improper input validation in the Alerts controller, a SQL injection vulnerability in Nozomi Networks Guardian and CMC allows an authenticated attacker to execute arbitrary S
May 4, 20238.828NONO
CVE-2026-31983MEDIUM
A Missing Authentication vulnerability was discovered in the SSH keys synchronization endpoint. An unauthenticated attacker can send a request to the SSH keys synchronization endpo
Jul 9, 20265.327NONO
CVE-2026-31981MEDIUM
A Stored HTML Injection vulnerability was discovered in the Diagram tab and Graph view due to a shared input validation function being insufficiently restrictive. An authenticated
Jul 9, 20264.826NONO
CVE-2025-3719HIGH
An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges. An authe
Oct 7, 20258.126NONO
CVE-2025-40898HIGH
A path traversal vulnerability was discovered in the Import Arc data archive functionality due to insufficient validation of the input file. An authenticated user with limited priv
Dec 18, 20258.124NONO
View all 45 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products45 CVEs
56%
44%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (4.4%)
Network43 (95.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low40 (88.9%)
High5 (11.1%)
Unknown0 (0.0%)
User Interaction
None29 (64.4%)
Unknown0 (0.0%)
Required16 (35.6%)
Privileges Required
Low23 (51.1%)
High11 (24.4%)
None11 (24.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nozominetworks.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nozominetworks — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nozominetworks's Products

View all 2 CNAs →

Top CWEs