Severity: High
CVE ID: CVE-2026-76980
| Product name | Affected Version(s) | Fixed Version(s) | Fixed On |
|---|---|---|---|
| OpManager OpManager Enterprise Edition OpManager Nexus OpManager Nexus Enterprise Edition Firewall Analyzer | 12.8.709 and below | 12.8.710 and above* | 14-08-2026 |
| 12.8.718 to 12.9.122 | 12.9.124 and above* | 20-08-2026 |
Note: This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled.
Details:
Firewall Analyzer's syslog collector previously accepted incoming syslog datagrams and used the source host information to update the device IP associated with a monitored firewall. This could cause the product to consider an attacker-controlled host for a subsequent CLI configuration connection. This issue has now been fixed.
Impact:
A remote attacker who can send UDP traffic to the syslog listener could cause Firewall Analyzer to establish a CLI configuration session to a malicious host, exposing stored credentials for a managed firewall to an unauthorized party.
Fix:
Firewall Analyzer no longer uses the syslog source host for CLI configuration connections. The product continues to use the original IP address configured when the device credentials was added.
Steps to upgrade:
Source and Acknowledgements
This vulnerability was reported by qquynh.
Kindly contact our product support teams for further details, at the email address mentioned below: