CVE-2026-31985 Details
Description
When the upstream Guardian or CMC was configured in the Remote Collector via n2os-tui, the generated configuration disabled TLS certificate verification, and no option was provided to enable it. A malicious actor could perform a man-in-the-middle attack and intercept the communication between the Remote Collector and the Guardian or CMC. This could result in theft of the sync token, impersonation of the server, injection of spoofed data (such as false asset information or vulnerabilities) into the Guardian or CMC, or disruption of the data flow between the Remote Collector and the Guardian or CMC.
A vulnerability exists in Nozomi Networks Remote Collector versions prior to 26.2.0, where the n2os-tui interface disables TLS certificate verification when connecting to an upstream Guardian or CMC. This lack of validation, combined with the absence of an option to re-enable it, exposes users to potential man-in-the-middle attacks. Such attacks could intercept communications, steal sync tokens, impersonate servers, inject false asset information or vulnerabilities into the Guardian or CMC, and disrupt data flow between the Remote Collector and these services.
Users can manually edit the 'n2os.conf.user' file in the Remote Collector to enable TLS certificate verification by removing the '!' prefix from the upstream Guardian or CMC endpoint entry. Alternatively, upgrading the Remote Collector to version 26.2.0 or later will also address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.nozominetworks.com/NN-2026:12-01 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-671 | Lack of Administrator Control over Security | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | CISA-ADP |
| Jul 9, 2026 | New CVE Received | [email protected] |