Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Netact MEDIUM 6.5
CVE-2023-26057

An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper X…

Mitigation only
Fix from $1,600 2023-04-25
Netact MEDIUM 6.5
CVE-2023-26058

An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML par…

Mitigation only
Fix from $1,600 2023-04-25
Netact MEDIUM 5.4
CVE-2023-26059

An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, …

Mitigation only
Fix from $1,600 2023-04-24
Netact HIGH 8.8
CVE-2023-26060

An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Set with a name that has a clie…

Fix: 20.1+
Fix from $1,950 2023-04-24
Netact MEDIUM 5.4
CVE-2023-26061

An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard page, users can create a scri…

Fix: after 20.1
Fix from $1,600 2023-04-24
Asik Airscale 474021a.102 Firmware HIGH 8.8
CVE-2022-2482

A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script o…

Mitigation only
Fix from $1,950 2023-01-06
Asik Airscale 474021a.101 Firmware HIGH 7.8
CVE-2022-2484

The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This …

Mitigation only
Fix from $1,950 2023-01-06
Asik Airscale 474021a.102 Firmware HIGH 7.1
CVE-2022-2483

The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature.…

Mitigation only
Fix from $1,950 2023-01-06
Fastmile Firmware HIGH 8.4
CVE-2022-36222

Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used…

No fix yet
Fix from $1,950 2022-12-21
Fastmile Firmware MEDIUM 6.5
CVE-2022-36221

Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to read any named pipe file on the …

No fix yet
Fix from $1,600 2022-12-21
Airframe Bmc Web Gui R18 Firmware HIGH 8.8
CVE-2022-28866

Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for acc…

Fix: 4.13.00+
Fix from $1,950 2022-10-12
1350 Optical Management System MEDIUM 6.5
CVE-2022-40713

An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter,…

Mitigation only
Fix from $1,600 2022-09-19
1350 Optical Management System MEDIUM 6.5
CVE-2022-40715

An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, al…

Mitigation only
Fix from $1,600 2022-09-19
1350 Optical Management System MEDIUM 6.1
CVE-2022-40712

An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.

Mitigation only
Fix from $1,600 2022-09-19
1350 Optical Management System MEDIUM 6.1
CVE-2022-40714

An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /oms1350/* endpoints.

Mitigation only
Fix from $1,600 2022-09-19
1350 Optical Management System HIGH 8.8
CVE-2022-39819

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating s…

Mitigation only
Fix from $1,950 2022-09-13
1350 Optical Management System HIGH 7.5
CVE-2022-39821

In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical…

Mitigation only
Fix from $1,950 2022-09-13
1350 Optical Management System CRITICAL 9.8
CVE-2022-39815

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on …

Mitigation only
Fix from $2,300 2022-09-13
1350 Optical Management System HIGH 8.8
CVE-2022-39817

In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arb…

Mitigation only
Fix from $1,950 2022-09-13
1350 Optical Management System MEDIUM 6.5
CVE-2022-39816

In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation r…

Mitigation only
Fix from $1,600 2022-09-13
1350 Optical Management System MEDIUM 6.1
CVE-2022-39814

In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.

Mitigation only
Fix from $1,600 2022-09-13
Vitalsuite CRITICAL 9.8
CVE-2021-41487

NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.

No fix yet
Fix from $2,300 2022-06-16
Broadcast Message Center MEDIUM 6.5
CVE-2021-35487

Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/bloc…

Fix: after 11.1.0
Fix from $1,600 2022-05-25
Bts Trs Web Console CRITICAL 9.8
CVE-2021-31932EPSS 22%

Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functi…

No fix yet
Fix from $2,300 2022-02-11
Fastmile Firmware HIGH 8.8
CVE-2021-45896

Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import C…

No fix yet
Fix from $1,950 2021-12-27
Heif HIGH 7.8
CVE-2021-32287

An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located…

Fix: after 3.6.2
Fix from $1,950 2021-09-20
Heif HIGH 7.8
CVE-2021-32288

An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() locate…

Fix: after 3.6.2
Fix from $1,950 2021-09-20
Heif MEDIUM 5.5
CVE-2021-32289

An issue was discovered in heif through through v3.6.2. A NULL pointer dereference exists in the function convertByteStreamToRBSP() located in naluti…

Fix: after 3.6.2
Fix from $1,600 2021-09-20
Netact MEDIUM 6.5
CVE-2021-26597

An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web sit…

No fix yet
Fix from $1,600 2021-03-25
Netact MEDIUM 5.4
CVE-2021-26596

An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then sto…

No fix yet
Fix from $1,600 2021-03-25