{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2023-2567", "ASSIGNER": "prodsec@nozominetworks.com", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "A SQL Injection vulnerability has been found in Nozomi Networks Guardian and CMC, due to improper input validation in certain parameters used in the Query functionality.\nAuthenticated users may be able to execute arbitrary SQL statements on the DBMS used by the web application." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')", "cweId": "CWE-89" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Nozomi Networks", "product": { "product_data": [ { "product_name": "Guardian", "version": { "version_data": [ { "version_affected": "<", "version_name": "0", "version_value": "22.6.3" }, { "version_affected": "<", "version_name": "23.0.0", "version_value": "23.1.0" } ] } }, { "product_name": "CMC", "version": { "version_data": [ { "version_affected": "<", "version_name": "0", "version_value": "22.6.3" }, { "version_affected": "<", "version_name": "23.0.0", "version_value": "23.1.0" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://security.nozominetworks.com/NN-2023:9-01", "refsource": "MISC", "name": "https://security.nozominetworks.com/NN-2023:9-01" } ] }, "generator": { "engine": "Vulnogram 0.1.0-dev" }, "source": { "discovery": "EXTERNAL" }, "work_around": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "