Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hit 7300 Firmware HIGH 8.4
CVE-2024-28813

An issue was discovered in Infinera hiT 7300 5.60.50. Undocumented privileged functions in the @CT management application allow an attacker to activa…

Mitigation only
Fix from $1,950 2024-09-30
Hit 7300 Firmware MEDIUM 6.6
CVE-2024-28810

An issue was discovered in Infinera hiT 7300 5.60.50. Sensitive information inside diagnostic files (exported by the @CT application) allows an attac…

Mitigation only
Fix from $1,600 2024-09-30
Hit 7300 Firmware HIGH 8.8
CVE-2024-28809

An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access …

Mitigation only
Fix from $1,950 2024-09-30
Network Functions Manager For Transport HIGH 8.8
CVE-2022-39822

In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET paramete…

No fix yet
Fix from $1,950 2023-12-25
Network Functions Manager For Transport MEDIUM 6.5
CVE-2022-39820

In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport MEDIUM 6.5
CVE-2022-41760

An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the fi…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport MEDIUM 6.5
CVE-2022-41761

An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport MEDIUM 6.1
CVE-2022-41762

An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport MEDIUM 6.1
CVE-2022-43675

An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filena…

No fix yet
Fix from $1,600 2023-12-25
Network Functions Manager For Transport HIGH 8.8
CVE-2022-39818

In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. T…

No fix yet
Fix from $1,950 2023-12-25
G 040w Q Firmware CRITICAL 9.8
CVE-2023-41351

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentic…

Mitigation only
Fix from $2,300 2023-11-03
G 040w Q Firmware CRITICAL 9.8
CVE-2023-41355

Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attac…

Mitigation only
Fix from $2,300 2023-11-03
G 040w Q Firmware HIGH 8.8
CVE-2023-41353

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the…

Mitigation only
Fix from $1,950 2023-11-03
G 040w Q Firmware HIGH 7.2
CVE-2023-41352

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can expl…

Mitigation only
Fix from $1,950 2023-11-03
G 040w Q Firmware MEDIUM 5.3
CVE-2023-41354

Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit t…

Mitigation only
Fix from $1,600 2023-11-03
G 040w Q Firmware CRITICAL 9.8
CVE-2023-41350

Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated r…

Mitigation only
Fix from $2,300 2023-11-03
Wavelite Metro 200 And Fan Firmware HIGH 7.8
CVE-2023-22618

If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privilege…

Mitigation only
Fix from $1,950 2023-10-04
Access Management System HIGH 8.8
CVE-2022-41763

An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to…

No fix yet
Fix from $1,950 2023-09-05
Service Router Linux HIGH 7.5
CVE-2023-41376

Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attri…

No fix yet
Fix from $1,950 2023-08-29
Netact HIGH 8.8
CVE-2022-28863

An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitraril…

No fix yet
Fix from $1,950 2023-07-24
Netact HIGH 8.8
CVE-2022-28864

An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateN…

No fix yet
Fix from $1,950 2023-07-24
Netact HIGH 8.8
CVE-2022-30280

/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even adm…

No fix yet
Fix from $1,950 2023-07-24
Netact MEDIUM 5.4
CVE-2022-28865

An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded…

No fix yet
Fix from $1,600 2023-07-24
Netact MEDIUM 5.4
CVE-2022-28867

An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateN…

No fix yet
Fix from $1,600 2023-07-24
Asika Airscale Firmware HIGH 7.0
CVE-2023-25187

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time …

No fix yet
Fix from $1,950 2023-06-16
Asika Airscale Firmware HIGH 7.8
CVE-2023-25185

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN…

Mitigation only
Fix from $1,950 2023-06-16
Asika Airscale Firmware HIGH 7.8
CVE-2023-25188

An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from …

Mitigation only
Fix from $1,950 2023-06-16
Web Element Manager HIGH 7.8
CVE-2023-26062

A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute…

Fix: 22r1+
Fix from $1,950 2023-06-14
One Nds HIGH 8.8
CVE-2022-30759

In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and…

Fix: after 20.9
Fix from $1,950 2023-05-02
One Network Directory Server HIGH 7.8
CVE-2022-31244

Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.

No fix yet
Fix from $1,950 2023-04-25