📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Government and Defense CRITICAL 24m Global general Technology / Consumer Protection MEDIUM 35m Global vulnerability Information Technology and Security CRITICAL 43m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 24m Global general Technology / Consumer Protection MEDIUM 35m Global vulnerability Information Technology and Security CRITICAL 43m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h Global apt Government and Defense CRITICAL 24m Global general Technology / Consumer Protection MEDIUM 35m Global vulnerability Information Technology and Security CRITICAL 43m Global vulnerability Information Technology CRITICAL 1h Global apt Infrastructure, Transportation, Finance/Investment HIGH 1h Global vulnerability Information Technology and Infrastructure HIGH 2h Global data_breach Education HIGH 3h Global data_breach Education HIGH 4h Global vulnerability Information Technology CRITICAL 4h Global supply_chain Software Development and Technology HIGH 5h
Vulnerabilities

CVE-2025-40902

Medium
CWE-79 — Weakness Type
Published: May 19, 2026  ·  Modified: May 22, 2026  ·  Source: NVD
CVSS v3
5.9
🔗 NVD Official
📄 Description (English)

A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing the affected user, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.

🤖 AI Executive Summary

CVE-2025-40902 is a stored HTML injection vulnerability in Nozomi Networks CMC and Guardian that allows authenticated administrators to inject malicious HTML into usernames. When other administrators attempt to delete groups containing affected users, the injected HTML renders in their browsers, enabling phishing and open redirect attacks. While full XSS exploitation is mitigated by CSP, the vulnerability poses a significant risk to administrative workflows in critical infrastructure environments. No patch is currently available, requiring immediate compensating controls.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 24, 2026 11:20
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi organizations operating critical infrastructure monitoring systems, particularly: (1) Energy sector (ARAMCO, regional utilities) using Nozomi Guardian for OT/ICS monitoring; (2) Government agencies and NCA utilizing CMC for network management; (3) Telecom operators (STC, Mobily) managing critical network infrastructure; (4) Healthcare facilities with connected medical devices. The risk is elevated in Saudi environments where administrative access is often centralized and group management is frequent. Phishing attacks targeting administrators could lead to credential compromise and lateral movement within critical systems.
🏢 Affected Saudi Sectors
Energy (ARAMCO, utilities) Government (NCA, federal agencies) Telecommunications (STC, Mobily) Healthcare Critical Infrastructure
⚖️ Saudi Risk Score (AI)
6.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Audit all user accounts in CMC and Guardian systems for suspicious usernames containing HTML tags or special characters
2. Restrict administrative user creation privileges to a minimal set of trusted personnel
3. Implement mandatory review process for new user account creation with HTML/special character validation
4. Document all current administrative users and their creation dates

Compensating Controls:
1. Deploy email security controls to detect and block phishing emails referencing CMC/Guardian administrative tasks
2. Implement multi-factor authentication (MFA) for all administrative accounts accessing CMC/Guardian
3. Enable detailed audit logging for user creation, modification, and group deletion operations
4. Configure browser security policies to restrict administrative access to trusted networks only
5. Implement network segmentation isolating CMC/Guardian administrative interfaces

Detection Rules:
1. Monitor for user creation events with usernames containing: <, >, ", ', &, javascript:, onerror=, onclick=
2. Alert on group deletion operations followed by administrator credential usage anomalies
3. Log and review all administrative interface access from unusual geographic locations or times
4. Monitor for CSP violation reports in browser console logs

Patching Strategy:
1. Contact Nozomi Networks for patch availability timeline
2. Prepare isolated test environment for patch validation when available
3. Schedule maintenance window for production deployment
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع حسابات المستخدمين في أنظمة CMC و Guardian بحثاً عن أسماء مستخدمين مريبة تحتوي على علامات HTML أو أحرف خاصة
2. تقييد امتيازات إنشاء المستخدم الإداري لمجموعة صغيرة من الموظفين الموثوقين
3. تنفيذ عملية مراجعة إلزامية لإنشاء حسابات المستخدمين الجديدة مع التحقق من HTML والأحرف الخاصة
4. توثيق جميع المستخدمين الإداريين الحاليين وتواريخ إنشاؤهم

الضوابط التعويضية:
1. نشر ضوابط أمان البريد الإلكتروني للكشف عن رسائل التصيد الاحتيالي وحجبها التي تشير إلى مهام CMC/Guardian الإدارية
2. تنفيذ المصادقة متعددة العوامل (MFA) لجميع الحسابات الإدارية التي تصل إلى CMC/Guardian
3. تفعيل تسجيل التدقيق التفصيلي لعمليات إنشاء المستخدم والتعديل وحذف المجموعة
4. تكوين سياسات أمان المتصفح لتقييد الوصول الإداري إلى الشبكات الموثوقة فقط
5. تنفيذ تقسيم الشبكة لعزل واجهات CMC/Guardian الإدارية

قواعد الكشف:
1. مراقبة أحداث إنشاء المستخدم مع أسماء مستخدمين تحتوي على: <، >، "، '، &، javascript:، onerror=، onclick=
2. التنبيه على عمليات حذف المجموعة متبوعة بشذوذ استخدام بيانات اعتماد المسؤول
3. تسجيل ومراجعة جميع عمليات الوصول إلى الواجهة الإدارية من مواقع جغرافية أو أوقات غير عادية
4. مراقبة تقارير انتهاك CSP في سجلات وحدة تحكم المتصفح

استراتيجية التصحيح:
1. الاتصال بـ Nozomi Networks للحصول على الجدول الزمني لتوفر التصحيح
2. تحضير بيئة اختبار معزولة للتحقق من صحة التصحيح عند توفره
3. جدولة نافذة الصيانة لنشر الإنتاج
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
5.1.1 - Access Control and Authentication 5.2.1 - Input Validation and Output Encoding 5.3.2 - Security Event Logging and Monitoring 5.4.1 - Vulnerability Management
🔵 SAMA CSF
ID.AM-2 - Software Inventory PR.AC-1 - Access Control PR.PT-1 - Security Awareness and Training DE.CM-1 - Detection and Analysis
🟡 ISO 27001:2022
A.5.15 - Access Control A.5.16 - Cryptography A.8.22 - Monitoring A.12.6.1 - Management of Technical Vulnerabilities
📦 Affected Products / CPE 2 entries
nozominetworks:cmc
nozominetworks:guardian
📊 CVSS Score
5.9
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredH — High
User InteractionR — Required
ScopeC — Changed
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score5.9
CWECWE-79
EPSS0.03%
Exploit No
Patch ✗ No
Published 2026-05-19
Source Feed nvd
🇸🇦 Saudi Risk Score
6.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-79
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.