---
id: CVE-2026-33389
title: >-
  An improper certificate/host key validation vulnerability was discovered in
  the Smart Polling functionality, which established encrypted connections to
  target devices without validating the remote host's identity, and no option
  was provi…
summary: >-
  An improper certificate/host key validation vulnerability was discovered in
  the Smart Polling functionality, which established encrypted connections to
  target devices without validating the remote host's identity, and no option
  was provi…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:L'
cwe:
  - CWE-671
vendor: Nozomi Networks
product: Guardian
affected:
  - Guardian < 26.3.0
  - CMC < 26.3.0
  - Arc < 2.7.0
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:12:59.557'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33389'
references:
  - url: 'https://security.nozominetworks.com/NN-2026:20-01'
    label: prodsec@nozominetworks.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T14:19:40.637992Z'
ingestedAt: '2026-09-08T15:33:26.984Z'
epss: 0.00159
epssPercentile: 0.04238
---

## Overview

An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it. A man-in-the-middle attacker positioned between a sensor and a polled device can, during a polling session, impersonate the device and intercept the communication, including the credentials used to access it. The captured credentials can then be replayed to authenticate against the device itself or against other devices sharing the same credentials, allowing the attacker to access and tamper with the device's data and to disrupt its operations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
