CVE-2024-13089

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
10/06/2025
Last modified:
12/06/2025

Description

An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS commands.<br /> <br /> <br /> <br /> Users with administrative privileges may upload update packages to upgrade the versions of Nozomi Networks Guardian and CMC.<br /> <br /> While these updates are signed and their signatures are validated prior to installation, an improper signature validation check has been identified.<br /> <br /> This issue could potentially enable users to execute commands remotely on the appliance, thereby impacting confidentiality, integrity, and availability.

References to Advisories, Solutions, and Tools