Vulnerability index

Browse CVEs

83 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Netact HIGH 8.8
CVE-2022-28864

An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateN…

No fix yet
Fix from $1,950 2023-07-24
Netact HIGH 8.8
CVE-2022-30280

/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even adm…

No fix yet
Fix from $1,950 2023-07-24
Netact MEDIUM 5.4
CVE-2022-28865

An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded…

No fix yet
Fix from $1,600 2023-07-24
Netact MEDIUM 5.4
CVE-2022-28867

An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateN…

No fix yet
Fix from $1,600 2023-07-24
Asika Airscale Firmware HIGH 7.0
CVE-2023-25187

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time …

No fix yet
Fix from $1,950 2023-06-16
Asika Airscale Firmware HIGH 7.8
CVE-2023-25185

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN…

Mitigation only
Fix from $1,950 2023-06-16
Asika Airscale Firmware HIGH 7.8
CVE-2023-25188

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from …

Mitigation only
Fix from $1,950 2023-06-16
One Network Directory Server HIGH 7.8
CVE-2022-31244

Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.

No fix yet
Fix from $1,950 2023-04-25
Netact MEDIUM 6.5
CVE-2023-26057

An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper X…

Mitigation only
Fix from $1,600 2023-04-25
Netact MEDIUM 6.5
CVE-2023-26058

An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML par…

Mitigation only
Fix from $1,600 2023-04-25
Netact MEDIUM 5.4
CVE-2023-26059

An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, …

Mitigation only
Fix from $1,600 2023-04-24
Asik Airscale 474021a.102 Firmware HIGH 8.8
CVE-2022-2482

A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script o…

Mitigation only
Fix from $1,950 2023-01-06
Asik Airscale 474021a.101 Firmware HIGH 7.8
CVE-2022-2484

The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This …

Mitigation only
Fix from $1,950 2023-01-06
Asik Airscale 474021a.102 Firmware HIGH 7.1
CVE-2022-2483

The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature.…

Mitigation only
Fix from $1,950 2023-01-06
Fastmile Firmware HIGH 8.4
CVE-2022-36222

Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used…

No fix yet
Fix from $1,950 2022-12-21
Fastmile Firmware MEDIUM 6.5
CVE-2022-36221

Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to read any named pipe file on the …

No fix yet
Fix from $1,600 2022-12-21
1350 Optical Management System MEDIUM 6.5
CVE-2022-40713

An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter,…

Mitigation only
Fix from $1,600 2022-09-19
1350 Optical Management System MEDIUM 6.5
CVE-2022-40715

An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, al…

Mitigation only
Fix from $1,600 2022-09-19
1350 Optical Management System MEDIUM 6.1
CVE-2022-40712

An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.

Mitigation only
Fix from $1,600 2022-09-19
1350 Optical Management System MEDIUM 6.1
CVE-2022-40714

An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /oms1350/* endpoints.

Mitigation only
Fix from $1,600 2022-09-19
1350 Optical Management System HIGH 8.8
CVE-2022-39819

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating s…

Mitigation only
Fix from $1,950 2022-09-13
1350 Optical Management System HIGH 7.5
CVE-2022-39821

In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical…

Mitigation only
Fix from $1,950 2022-09-13
1350 Optical Management System CRITICAL 9.8
CVE-2022-39815

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on …

Mitigation only
Fix from $2,300 2022-09-13
1350 Optical Management System HIGH 8.8
CVE-2022-39817

In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arb…

Mitigation only
Fix from $1,950 2022-09-13
1350 Optical Management System MEDIUM 6.5
CVE-2022-39816

In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation r…

Mitigation only
Fix from $1,600 2022-09-13
1350 Optical Management System MEDIUM 6.1
CVE-2022-39814

In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.

Mitigation only
Fix from $1,600 2022-09-13
Vitalsuite CRITICAL 9.8
CVE-2021-41487

NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.

No fix yet
Fix from $2,300 2022-06-16
Bts Trs Web Console CRITICAL 9.8
CVE-2021-31932EPSS 22%

Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functi…

No fix yet
Fix from $2,300 2022-02-11
Fastmile Firmware HIGH 8.8
CVE-2021-45896

Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import C…

No fix yet
Fix from $1,950 2021-12-27
Netact MEDIUM 6.5
CVE-2021-26597

An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web sit…

No fix yet
Fix from $1,600 2021-03-25