Vulnerabilities > Nozominetworks > CMC > 22.6.0

DATE CVE VULNERABILITY TITLE RISK
2023-08-09 CVE-2023-24471 Incorrect Authorization vulnerability in Nozominetworks CMC and Guardian
An access control vulnerability was found, due to the restrictions that are applied on actual assertions not being enforced in their debug functionality. An authenticated user with reduced visibility can obtain unauthorized information via the debug functionality, obtaining data that would normally be not accessible in the Query and Assertions functions.
network
low complexity
nozominetworks CWE-863
6.5
2023-08-09 CVE-2023-24477 Session Fixation vulnerability in Nozominetworks CMC and Guardian
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC versions before 22.6.2 do not always completely invalidate the user session upon logout.
local
high complexity
nozominetworks CWE-384
7.0