Status: UPDATED
| Advisory ID: CVE-2026-33390
Key Details
| CVE | CVE-2026-33390 |
| CVSS Score / Version | 8.1 (High) / CVSS v3.1 |
| Updated | 2026-08-11 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is high; availability impact is high. |
| Affected products | Nozomi Networks Guardian, Nozomi Networks CMC, and Siemens RUGGEDCOM APE1808 |
| Classified as | CWE-266 (Incorrect Privilege Assignment) |
| Exploitation prediction (EPSS) | 0.40% probability of exploitation in the next 30 days (32% percentile) -- FIRST.org's EPSS model. |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
An Incorrect Privilege Assignment vulnerability was discovered in the synchronization functionality due to Arc sensors receiving CLI permissions. An authenticated user with limited privileges can push administrative CLI commands through the sync, altering the device configuration, and/or affecting its availability. (NVD)
What to Do
Monitor Nozomi Networks's and Siemens's web pages for any future patch releases. See vendor advisory link below.
References