Data Exposure vulnerability- CVE-2026-76980

Severity: High

CVE ID: CVE-2026-76980

Product nameAffected Version(s)Fixed Version(s)Fixed On
OpManager
OpManager Enterprise Edition
OpManager Nexus
OpManager Nexus Enterprise Edition
Firewall Analyzer
12.8.709 and below12.8.710 and above*14-08-2026
12.8.718 to 12.9.12212.9.124 and above*20-08-2026

Note: This security vulnerability is applicable only for users of Firewall Analyzer, and for OpManager/Enterprise Edition/Nexus users with the Firewall Analyzer Plugin enabled.

Details:

Firewall Analyzer's syslog collector previously accepted incoming syslog datagrams and used the source host information to update the device IP associated with a monitored firewall. This could cause the product to consider an attacker-controlled host for a subsequent CLI configuration connection. This issue has now been fixed.

Impact:

A remote attacker who can send UDP traffic to the syslog listener could cause Firewall Analyzer to establish a CLI configuration session to a malicious host, exposing stored credentials for a managed firewall to an unauthorized party.

Fix:

Firewall Analyzer no longer uses the syslog source host for CLI configuration connections. The product continues to use the original IP address configured when the device credentials was added.

Steps to upgrade:

  1. Download the latest upgrade pack from here.
  2. Apply the latest build to your existing product installation as per the upgrade pack instructions provided in the above step.

Source and Acknowledgements

This vulnerability was reported by qquynh.

Kindly contact our product support teams for further details, at the email address mentioned below: