Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Stored XSS in Nozomi Guardian/CMC Reports Functionality

IdentifiersCVE-2025-40892CWE-79· Improper Neutralization of Input…

CVE-2025-40892 is a stored cross-site scripting vulnerability in the Reports functionality of Nozomi Guardian/CMC before version 25.5.0. The issue is caused by improper validation of an input parameter used in report definitions/templates. An authenticated user with report privileges can create a malicious report containing attacker-controlled JavaScript, or a victim can be induced to import a malicious report template. When another user views or imports the crafted report, the payload executes in that user’s browser context within the application session. The flaw affects Guardian/CMC deployments, including Siemens RUGGEDCOM APE1808 deployments that incorporate the vulnerable software.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows execution of attacker-supplied JavaScript in the victim’s authenticated browser session. This can be used to perform unauthorized actions as the victim within the application, including modifying application data, disrupting application availability, and accessing limited sensitive information available to that user. The advisory rates the issue as high severity with CVSS v3.1 8.9 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H), reflecting the potential for significant integrity and availability impact with some confidentiality impact.

Mitigation

If you can’t patch tonight, do this now.

Until patches are applied, restrict report creation/import capabilities to only trusted users, review and remove untrusted or unexpected report templates, and apply strict server-side input validation and context-appropriate output encoding for report parameters and rendered content. Reduce exposure of the management interface, limit access through network segmentation and firewalls, and use secure remote access methods. In ICS environments, follow Siemens/CISA hardening guidance by minimizing internet exposure of affected systems and isolating control-system networks from business or public networks.

Remediation

Patch, then assume compromise.

Upgrade Nozomi Guardian/CMC to version 25.5.0 or later. For Siemens-integrated deployments such as RUGGEDCOM APE1808, Siemens states customers should contact customer support to obtain patch and update information, and notes that fixed versions are being prepared/published through vendor channels. Where product-specific update guidance exists, follow the vendor advisory and apply the relevant software/firmware update as soon as operationally feasible.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Nozomi NetworksCmcapplication
Nozomi NetworksGuardianapplication
NozominetworksCmcapplication
NozominetworksGuardianapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity4

Community discussion across Reddit, Mastodon, and other social sources.