CVE-2025-40891
中文标题:
(暂无数据)
英文标题:
HTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0
漏洞描述
中文描述:
(暂无数据)
英文描述:
A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic data. An unauthenticated attacker can send specially crafted network packets at two different times to inject HTML tags into asset attributes across two snapshots. Exploitation requires a victim to use the Time Machine Snapshot Diff feature on those specific snapshots and perform specific GUI actions, at which point the injected HTML renders in their browser, enabling phishing and open redirect attacks. Full XSS exploitation is prevented by input validation and Content Security Policy. Attack complexity is high due to multiple required conditions.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Nozomi Networks | Guardian | - | < 25.5.0 | - |
cpe:2.3:a:nozomi_networks:guardian:*:*:*:*:*:*:*:*
|
| Nozomi Networks | CMC | - | < 25.5.0 | - |
cpe:2.3:a:nozomi_networks:cmc:*:*:*:*:*:*:*:*
|
| nozominetworks | cmc | * | - | - |
cpe:2.3:a:nozominetworks:cmc:*:*:*:*:*:*:*:*
|
| nozominetworks | guardian | * | - | - |
cpe:2.3:a:nozominetworks:guardian:*:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
CVSS评分详情
4.0 (cna)
LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
3.1 (cna)
MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-40891 |
2025-12-19 03:24:16 | 2026-01-12 02:11:48 |
| NVD | nvd_CVE-2025-40891 |
2026-01-07 03:00:07 | 2026-01-12 02:27:47 |
版本与语言
安全公告
变更历史
查看详细变更
- affected_products_count: 2 -> 4
- data_sources: ['cve'] -> ['cve', 'nvd']