Show filters
114 Total Results
Displaying 21-30 of 114
Sort by:
Attacker Value
Unknown
CVE-2022-28865
Disclosure Date: July 24, 2023 (last updated October 08, 2023)
An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.
0
Attacker Value
Unknown
CVE-2022-28864
Disclosure Date: July 24, 2023 (last updated October 08, 2023)
An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim machine. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.
0
Attacker Value
Unknown
CVE-2022-28863
Disclosure Date: July 24, 2023 (last updated October 08, 2023)
An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.
0
Attacker Value
Unknown
CVE-2023-25187
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time installed) default SSH public/private key values that are specific to a network operator. As a result, the CSP internal BTS network SSH server (disabled by default) continues to apply the default SSH public/private key values. These keys don't give access to BTS, because service user authentication is username/password-based on top of SSH. Nokia factory installed default SSH keys are meant to be changed from operator-specific values during the BTS deployment commissioning phase. However, before the 21B release, BTS commissioning manuals did not provide instructions to change default SSH keys (to BTS operator-specific values). This leads to a possibility for malicious operations staff (inside a CSP network) to attempt MITM exploitation of BTS service user access, during the moments that SSH is enabled for Nokia service personnel to perform…
0
Attacker Value
Unknown
CVE-2023-25188
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows unauthenticated access from the mobile network solution internal BTS management network to the BTS embedded Linux operating-system level.
0
Attacker Value
Unknown
CVE-2023-25186
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from a Nokia Single RAN BTS baseband unit, a directory path traversal in the Nokia BTS baseband unit diagnostic tool AaShell (which is by default disabled) provides access to the BTS baseband unit internal filesystem from the mobile network solution internal BTS management network.
0
Attacker Value
Unknown
CVE-2023-25185
Disclosure Date: June 16, 2023 (last updated October 08, 2023)
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal software design have unnecessarily high privileges to BTS embedded operating system (OS) resources.
0
Attacker Value
Unknown
CVE-2023-26062
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that exploit is not possible from mobile network user UEs, from roaming networks, or from the Internet. Exploitation is possible only from a CSP (Communication Service Provider) mobile network solution internal BTS management network.
0
Attacker Value
Unknown
CVE-2022-30759
Disclosure Date: May 02, 2023 (last updated October 08, 2023)
In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and execute arbitrary commands.
0
Attacker Value
Unknown
CVE-2022-31244
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
0