Status: UPDATED
| Advisory ID: CVE-2026-33390
Key Details
| CVE | CVE-2026-33390 |
| CVSS Score / Version | 8.1 (High) / CVSS v3.1 |
| Updated | 2026-08-11 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high. |
| Affected products | Nozomi Networks Guardian, Nozomi Networks CMC, Siemens RUGGEDCOM APE1808, nozominetworks cmc, and nozominetworks guardian |
| Classified as | CWE-266 (Incorrect Privilege Assignment) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability. (NVD)
What to Do
Monitor Nozomi Networks, Siemens, and nozominetworks's web pages for any future patch releases. See vendor advisory link below.
References