Back to Database
Status published
High
CVE-2023-6916
Information disclosure via audit records for OpenAPI requests in Guardian/CMC before 23.4.1
Vulnerability Description
Audit records for OpenAPI requests may include sensitive information. This could lead to unauthorized accesses and privilege escalation.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-6916
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This issue was reported by Maciej Kosz.
More from Nozomi Networks
View All →CVE-2025-40904
HTML injection in Smart Polling in Guardian/CMC before 26.1.0
Medium
5.1
CVE-2025-40903
HTML injection in Schedule Restore Archive in Guardian/CMC before 26.1.0
Medium
4.8
CVE-2025-40902
HTML injection in Users in Guardian/CMC before 26.1.0
Medium
4.8
CVE-2025-40901
HTML injection in Credentials Manager in Guardian/CMC before 26.1.0
Medium
4.8
CVE-2025-40900
Angular template injection in Reports in Guardian/CMC before 26.1.0
Medium
5.1
Affected Vendor
Nozomi Networks
View all reports →Affected Software
Guardian, CMC
Vulnerable Versions:
0
Timeline
Official Publish:
April 10th, 2024
Last Modified:
September 20th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H