Status: UPDATED
| Advisory ID: CVE-2026-31984
Key Details
| CVE | CVE-2026-31984 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-08-11 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | Nozomi Networks Guardian, Nozomi Networks CMC, and Siemens RUGGEDCOM APE1808 |
| Classified as | CWE-770 (Allocation of Resources Without Limits or Throttling) |
| Exploitation prediction (EPSS) | 0.51% probability of exploitation in the next 30 days (41% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A denial-of-service vulnerability caused by unbounded resource allocation was discovered in the audit logging functionality, due to a missing size limit on input recorded into audit entries. An unauthenticated attacker can submit requests containing excessively large input that is recorded into audit entries, possibly exhausting the available disk space and rendering the system inoperable. (NVD)
What to Do
Monitor Nozomi Networks's and Siemens's web pages for any future patch releases. See vendor advisory link below.
References