CVE-2023-5253

A missing authentication check in the WebSocket channel used for the Check Point IoT integration in Nozomi Networks Guardian and CMC, may allow an unauthenticated attacker to obtain assets data without authentication. Malicious unauthenticated users with knowledge on the underlying system may be able to extract asset information.
References
Link Resource
https://security.nozominetworks.com/NN-2023:12-01 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-01-15 11:15

Updated : 2024-05-28 13:15


NVD link : CVE-2023-5253

Mitre link : CVE-2023-5253

CVE.ORG link : CVE-2023-5253


JSON object : View

Products Affected

nozominetworks

  • guardian
  • cmc
CWE
CWE-306

Missing Authentication for Critical Function