<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Nokia Mobile (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/nokia.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/nokia-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Nokia Mobile (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-24818 – Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24818</guid>
    <pubDate>Tue, 07 Apr 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24818</strong></p>
  <p>Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24817 – Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24817</guid>
    <pubDate>Tue, 07 Apr 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24817</strong></p>
  <p>Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35486 – A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35486</guid>
    <pubDate>Tue, 03 Mar 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35486</strong></p>
  <p>A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor the CSRF-NONCE cookie is validated.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35485 – The Applications component of Nokia IMPACT version through 19.11.2.10-2021011804...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35485</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35485</guid>
    <pubDate>Tue, 03 Mar 2026 18:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35485</strong></p>
  <p>The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35485">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35484 – Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35484</guid>
    <pubDate>Tue, 03 Mar 2026 18:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35484</strong></p>
  <p>Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24332 – Nokia Single RAN AirScale baseband allows an authenticated administrative user a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24332</guid>
    <pubDate>Wed, 02 Jul 2025 09:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24332</strong></p>
  <p>Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after performing a single login to the baseband system board. The baseband does not re-authenticate the user when they connect from the baseband system board to the baseband capacity boards using the internal bsoc SSH service, which is available only internally within the baseband and thro…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6729 – Nokia SR OS routers allow read-write access to the entire file system via SFTP o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6729</guid>
    <pubDate>Thu, 17 Oct 2024 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6729</strong></p>
  <p>Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access console." Consequently, a low privilege authenticated user with "access console" can read or replace the router configuration file as well as other files stored in the Compact Flash or SD card without using CLI commands. This type of attack can lead to a compromise or denial of…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46743 – In the Linux kernel, the following vulnerability has been resolved:

of/irq: Pre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46743</guid>
    <pubDate>Wed, 18 Sep 2024 08:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46743</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  of/irq: Prevent device address out-of-bounds read in interrupt map walk  When of_irq_parse_raw() is invoked with a device address smaller than the interrupt parent node (from #address-cells property), KASAN detects the following out-of-bounds read when populating the initial match table (dyndbg="func of_irq_parse_* +p"):    OF:…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38293 – Certain software builds for the Nokia C200 and Nokia C100 Android devices contai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38293</guid>
    <pubDate>Mon, 22 Apr 2024 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38293</strong></p>
  <p>Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') that allows local third-party apps to execute arbitrary AT commands in its context (radio user) via AT command injection due to inadequate access control and inadequate input filtering. No permissions or…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39822 – In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/eas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39822</guid>
    <pubDate>Mon, 25 Dec 2023 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39822</strong></p>
  <p>In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39818 – In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39818</guid>
    <pubDate>Mon, 25 Dec 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39818</strong></p>
  <p>In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41355 – Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41355</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41355</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41353 – Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirement...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41353</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41353</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41352 – Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41352</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41352</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41351 – Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41351</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41351</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41350 – Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41350</guid>
    <pubDate>Fri, 03 Nov 2023 05:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41350</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22618 – If Security Hardening guide rules are not followed, then Nokia WaveLite products...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22618</guid>
    <pubDate>Wed, 04 Oct 2023 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22618</strong></p>
  <p>If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite Metro 200 and F2B fans, WaveLite Metro 200 OPS and F2B fans, WaveLite Metro 200 NE and F2B fans, and WaveLite Metro 200…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41763 – An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41763</guid>
    <pubDate>Tue, 05 Sep 2023 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41763</strong></p>
  <p>An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41376 – Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-han...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41376</guid>
    <pubDate>Tue, 29 Aug 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41376</strong></p>
  <p>Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-30280 – /SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30280</guid>
    <pubDate>Mon, 24 Jul 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-30280</strong></p>
  <p>/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social engineering/phishing (such as sending a link via email or chat), an attacker may t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-28864 – An issue was discovered in Nokia NetAct 22 through the Administration of Measure...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28864</guid>
    <pubDate>Mon, 24 Jul 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-28864</strong></p>
  <p>An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim machine. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-28863 – An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28863</guid>
    <pubDate>Mon, 24 Jul 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-28863</strong></p>
  <p>An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26062 – A mobile network solution internal fault is found in Nokia Web Element Manager b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26062</guid>
    <pubDate>Wed, 14 Jun 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26062</strong></p>
  <p>A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that exploit is not possible from mobile network user UEs, from roaming networks, or from the Internet. Exploitation is possible…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-30759 – In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30759</guid>
    <pubDate>Tue, 02 May 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-30759</strong></p>
  <p>In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and execute arbitrary commands.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31244 – Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31244</guid>
    <pubDate>Tue, 25 Apr 2023 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31244</strong></p>
  <p>Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2484 – The signature check in the Nokia ASIK AirScale system module version 474021A.101...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2484</guid>
    <pubDate>Fri, 06 Jan 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2484</strong></p>
  <p>The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary programs, or modified Nokia programs.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-1274</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2483 – The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2483</guid>
    <pubDate>Fri, 06 Jan 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2483</strong></p>
  <p>The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-1282</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2482 – A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2482</guid>
    <pubDate>Fri, 06 Jan 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2482</strong></p>
  <p>A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-1274</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36222 – Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a defaul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36222</guid>
    <pubDate>Wed, 21 Dec 2022 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36222</strong></p>
  <p>Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-28866 – Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI &lt; ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28866</guid>
    <pubDate>Wed, 12 Oct 2022 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-28866</strong></p>
  <p>Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for access to (or editing of) data and functionality in all endpoints under /#settings/* and /api/settings/*. By not verifying the permissions for access to resources, it allows a potential attacker to view pages, with sensitive data, that are not allowed,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39821 – In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39821</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39821</strong></p>
  <p>In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39819 – In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39819</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39819</strong></p>
  <p>In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39819">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39817 – In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploita...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39817</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39817</strong></p>
  <p>In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39815 – In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39815</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39815</strong></p>
  <p>In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41487 – NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41487</guid>
    <pubDate>Thu, 16 Jun 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41487</strong></p>
  <p>NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-31932 – Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31932</guid>
    <pubDate>Fri, 11 Feb 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-31932</strong></p>
  <p>Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45896 – Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45896</guid>
    <pubDate>Mon, 27 Dec 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45896</strong></p>
  <p>Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17403 – Nokia IMPACT &lt; 18A: An unrestricted File Upload vulnerability was found that may...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17403</guid>
    <pubDate>Mon, 25 Nov 2019 15:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17403</strong></p>
  <p>Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-2619 – The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, As...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2619</guid>
    <pubDate>Wed, 14 Nov 2012 12:30:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-2619</strong></p>
  <p>The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung, and Sony products, allow remote attackers to cause a denial of service (out-of-bounds read and Wi-Fi outage) via an RSN 802.11i information element.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-1472 – The Nokia E75 phone with firmware before 211.12.01 allows physically proximate a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1472</guid>
    <pubDate>Tue, 29 Mar 2011 18:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-1472</strong></p>
  <p>The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-0498 – Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0498</guid>
    <pubDate>Thu, 20 Jan 2011 19:00:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-0498</strong></p>
  <p>Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long entry in a playlist (.npl) file.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2538 – The Nokia N95 running Symbian OS 9.2, N82, and N810 Internet Tablet allow remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2538</guid>
    <pubDate>Mon, 20 Jul 2009 18:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2538</strong></p>
  <p>The Nokia N95 running Symbian OS 9.2, N82, and N810 Internet Tablet allow remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2538">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2009-0734 – Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0734</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0734</guid>
    <pubDate>Wed, 25 Feb 2009 20:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2009-0734</strong></p>
  <p>Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0734">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-0649 – The web browser in Symbian OS on the Nokia N95 cell phone allows remote attacker...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-0649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-0649</guid>
    <pubDate>Fri, 20 Feb 2009 18:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-0649</strong></p>
  <p>The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) via JavaScript code that calls the setAttributeNode method.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-0649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-5827 – The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware automati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-5827</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-5827</guid>
    <pubDate>Fri, 02 Jan 2009 19:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-5827</strong></p>
  <p>The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware automatically installs software upon completing the download of a JAR file, which makes it easier for remote attackers to execute arbitrary code via a crafted URI record in an NDEF tag.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-16</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-5827">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-5826 – The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware allows r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-5826</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-5826</guid>
    <pubDate>Fri, 02 Jan 2009 19:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-5826</strong></p>
  <p>The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware allows remote attackers to cause a denial of service (device crash) via (1) a large value in the payload length field in an NDEF record, or a certain length for a (2) tel: or (3) sms: NDEF URI.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-5826">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-4135 – Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-4135</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-4135</guid>
    <pubDate>Fri, 19 Sep 2008 17:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-4135</strong></p>
  <p>Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device crash) via multiple deauthentication (DeAuth) frames.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-4135">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-3552 – Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and pos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3552</guid>
    <pubDate>Fri, 08 Aug 2008 19:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-3552</strong></p>
  <p>Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka "ISSUES 11-15." NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information.  However, because it is from a company l…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-3553 – Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3553</guid>
    <pubDate>Fri, 08 Aug 2008 19:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-3553</strong></p>
  <p>Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vectors, probably related to MIDP privilege escalation and persistent MIDlets, aka "ISSUES 3-10." NOTE: as of 20080807, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a company led by a well-known research…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-6371 – Nokia N95 cell phone with RM-159 12.0.013 firmware allows remote attackers to ca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-6371</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-6371</guid>
    <pubDate>Sat, 15 Dec 2007 01:46:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-6371</strong></p>
  <p>Nokia N95 cell phone with RM-159 12.0.013 firmware allows remote attackers to cause a denial of service (device inoperability) via a SIP INVITE message accompanied by an immediately subsequent SIP CANCEL message, followed by a second SIP INVITE message in a different session.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-6371">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-2591 – usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2591</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2591</guid>
    <pubDate>Fri, 11 May 2007 04:20:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-2591</strong></p>
  <p>usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in an update action.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2591">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-0797 – Nokia N70 cell phone allows remote attackers to cause a denial of service (reboo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-0797</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-0797</guid>
    <pubDate>Sun, 19 Feb 2006 21:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-0797</strong></p>
  <p>Nokia N70 cell phone allows remote attackers to cause a denial of service (reboot or shutdown) through a wireless Bluetooth connection via a malformed Logical Link Control and Adaptation Protocol (L2CAP) packet whose length field is less than the actual length of the packet, possibly triggering a buffer overflow, as demonstrated using the Bluetooth Stack Smasher (BSS).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-0797">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-2716 – The event_pin_code_request function in the btsrv daemon (btsrv.c) in Nokia Affix...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-2716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-2716</guid>
    <pubDate>Mon, 29 Aug 2005 20:14:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-2716</strong></p>
  <p>The event_pin_code_request function in the btsrv daemon (btsrv.c) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a Bluetooth device name.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-2716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2005-2277 – Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-2277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-2277</guid>
    <pubDate>Fri, 15 Jul 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2005-2277</strong></p>
  <p>Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename argument of a PUT command.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-2277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2005-2250 – Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-2250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-2250</guid>
    <pubDate>Wed, 13 Jul 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2005-2250</strong></p>
  <p>Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-2250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2003-0803 – Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2003-0803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2003-0803</guid>
    <pubDate>Mon, 06 Oct 2003 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2003-0803</strong></p>
  <p>Nokia Electronic Documentation (NED) 5.0 allows remote attackers to use NED as an open HTTP proxy via a URL in the location parameter, which NED accesses and returns to the user.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2003-0803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2002-0480 – ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2002-0480</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2002-0480</guid>
    <pubDate>Mon, 12 Aug 2002 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2002-0480</strong></p>
  <p>ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have connected, which could allow remote attackers to gain access to the device during installation.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2002-0480">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2001-0299 – Buffer overflow in Voyager web administration server for Nokia IP440 allows loca...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2001-0299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2001-0299</guid>
    <pubDate>Sat, 02 Jun 2001 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2001-0299</strong></p>
  <p>Buffer overflow in Voyager web administration server for Nokia IP440 allows local users to cause a denial of service, and possibly execute arbitrary commands, via a long URL.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2001-0299">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
