← All Advisories

CVE-2026-31984

Last refreshed2026-10-06

Status: UPDATED  |  Advisory ID: CVE-2026-31984

Key Details

CVECVE-2026-31984
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-08-11
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsNozomi Networks Guardian, Nozomi Networks CMC, Siemens RUGGEDCOM APE1808, nozominetworks cmc, and nozominetworks guardian
Classified asCWE-770 (Allocation of Resources Without Limits or Throttling)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Nozomi NetworksGuardian
Nozomi NetworksCMC
SiemensRUGGEDCOM APE1808
nozominetworkscmc
nozominetworksguardian
SubsystemsGeneral OT
SectorsMultiple

What to Know

A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker can submit requests containing excessively large input that is recorded into audit entries, possibly exhausting the available disk space and rendering the system inoperable. (NVD)

What to Do

Monitor Nozomi Networks, Siemens, and nozominetworks's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-31984
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-31984
Vendor advisoryhttps://security.nozominetworks.com/NN-2026:11-01