CVE-2026-33389
Awaiting Analysis Awaiting Analysis - Queue

Improper Certificate Validation in Smart Polling

Vulnerability report for CVE-2026-33389, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: Nozomi Networks Inc.

Description

An improper certificate/host key validation vulnerability was discovered in the Smart Polling functionality, which established encrypted connections to target devices without validating the remote host's identity, and no option was provided to enable it. A man-in-the-middle attacker positioned between a sensor and a polled device can, during a polling session, impersonate the device and intercept the communication, including the credentials used to access it. The captured credentials can then be replayed to authenticate against the device itself or against other devices sharing the same credentials, allowing the attacker to access and tamper with the device's data and to disrupt its operations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-30
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-29
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-671 The product uses security features in a way that prevents the product's administrator from tailoring security settings to reflect the environment in which the product is being used. This introduces resultant weaknesses or prevents it from operating at a level of security that is desired by the administrator.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper certificate or host key validation in Smart Polling functionality. It allows encrypted connections to target devices without verifying the remote host's identity. A man-in-the-middle attacker can impersonate a device during polling, intercept communications including credentials, and replay those credentials to access or tamper with device data or disrupt operations.

Detection Guidance

Detecting this vulnerability requires checking if your system uses Smart Polling functionality without host key validation. Monitor network traffic for unencrypted or improperly secured polling sessions. Inspect configuration files for Smart Polling settings and verify if host key validation is enabled or available as an option.

Impact Analysis

This vulnerability can allow attackers to intercept sensitive data, including credentials, during polling sessions. Attackers could gain unauthorized access to devices, tamper with their data, or disrupt operations. Devices sharing the same credentials are also at risk of compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality and integrity requirements in GDPR and HIPAA. Failure to validate host identities may result in non-compliance with security controls mandated by these regulations, potentially leading to legal and financial penalties.

Mitigation Strategies

Disable Smart Polling functionality if not essential. If Smart Polling must be used, ensure host key validation is enabled to prevent man-in-the-middle attacks. Rotate all credentials used by polling sessions immediately to prevent replay attacks. Isolate polling sessions to dedicated, secure network segments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-33389. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart