<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Nokia Mobile</title>
  <link>https://cvedaily.com/pages/tags/nokia.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/nokia.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Nokia Mobile</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:51 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2022-45899 – Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-45899</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-45899</guid>
    <pubDate>Fri, 08 May 2026 05:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-45899</strong></p>
  <p>Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-45899">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24819 – Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24819</guid>
    <pubDate>Tue, 07 Apr 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24819</strong></p>
  <p>Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.</p>
  <p><strong>CVSS:</strong> 5.7 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24819">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24818 – Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24818</guid>
    <pubDate>Tue, 07 Apr 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24818</strong></p>
  <p>Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24817 – Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24817</guid>
    <pubDate>Tue, 07 Apr 2026 16:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24817</strong></p>
  <p>Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-31044 – An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31044</guid>
    <pubDate>Tue, 03 Mar 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-31044</strong></p>
  <p>An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may attempt data exfiltration or other malicious activity when automatically executed by the spreadsheet…</p>
  <p><strong>CVSS:</strong> 2.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35486 – A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35486</guid>
    <pubDate>Tue, 03 Mar 2026 18:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35486</strong></p>
  <p>A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor the CSRF-NONCE cookie is validated.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35485 – The Applications component of Nokia IMPACT version through 19.11.2.10-2021011804...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35485</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35485</guid>
    <pubDate>Tue, 03 Mar 2026 18:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35485</strong></p>
  <p>The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35485">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-35484 – Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35484</guid>
    <pubDate>Tue, 03 Mar 2026 18:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-35484</strong></p>
  <p>Nokia IMPACT through 19.11.2.10-20210118042150283 allows an authenticated user to perform a Time-based Boolean Blind SQL Injection attack on the endpoint /ui/rest-proxy/campaign/statistic (for the View Campaign page) via the sortColumn HTTP GET parameter. This allows an attacker to access sensitive data from the database and obtain access to the database user, database name, and database version…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-35483 – The Applications component of Nokia IMPACT version through 19.11.2.10-2021011804...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35483</guid>
    <pubDate>Tue, 03 Mar 2026 18:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-35483</strong></p>
  <p>The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload JavaScript files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one. If an authenticated user visits the web page where the file is published, the JavaScript…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-0980 – Nokia SR Linux is vulnerable to an authentication vulnerability allowing unautho...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0980</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0980</guid>
    <pubDate>Wed, 07 Jan 2026 12:16:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-0980</strong></p>
  <p>Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service.  When exploited, an invalid validation allows JSON RPC access without providing valid authentication credentials.</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0980">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-65885 – An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian B...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65885</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65885</guid>
    <pubDate>Fri, 26 Dec 2025 15:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-65885</strong></p>
  <p>An issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight v6.7), Nokia E7 (Delight v1.3), Nokia C7 (Delight v6.7), Nokia 700 (Delight v1.2), Nokia 701 (Delight v1.1), Nokia 603 (Delight v1.0), Nokia 500 (Delight v1.2), Nokia E6 (Delight v1.0), Nokia Oro (Delight v1.0), and Vertu Constellation T (Delight v1.0) allowi…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65885">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-24335 – Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24335</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24335</guid>
    <pubDate>Wed, 02 Jul 2025 09:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-24335</strong></p>
  <p>Nokia Single RAN baseband software versions earlier than 24R1-SR 2.1 MP contain a SOAP message input validation flaw, which in theory could potentially be used for causing resource exhaustion in the Single RAN baseband OAM service.  No practical exploit has been detected for this flaw. However, the issue has been corrected starting from release 24R1-SR 2.1 MP by adding sufficient input validation…</p>
  <p><strong>CVSS:</strong> 2.0 · <strong>CWE:</strong> CWE-1287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24335">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-24334 – The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24334</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24334</guid>
    <pubDate>Wed, 02 Jul 2025 09:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-24334</strong></p>
  <p>The Nokia Single RAN baseband software earlier than 23R2-SR 1.0 MP can be made to reveal the exact software release version by sending a specific HTTP POST request through the Mobile Network Operator (MNO) internal RAN management network.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-497</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24334">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24333 – Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24333</guid>
    <pubDate>Wed, 02 Jul 2025 09:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24333</strong></p>
  <p>Nokia Single RAN baseband software earlier than 24R1-SR 1.0 MP contains administrative shell input validation fault, which authenticated admin user can, in theory, potentially use for injecting arbitrary commands for unprivileged baseband OAM service process execution via special characters added to baseband internal COMA_config.xml file.  This issue has been corrected starting from release 24R1-…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-24332 – Nokia Single RAN AirScale baseband allows an authenticated administrative user a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24332</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24332</guid>
    <pubDate>Wed, 02 Jul 2025 09:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-24332</strong></p>
  <p>Nokia Single RAN AirScale baseband allows an authenticated administrative user access to all physical boards after performing a single login to the baseband system board. The baseband does not re-authenticate the user when they connect from the baseband system board to the baseband capacity boards using the internal bsoc SSH service, which is available only internally within the baseband and thro…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24332">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24330 – Sending a crafted SOAP "provision" operation message PlanId field within the Mob...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24330</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24330</guid>
    <pubDate>Wed, 02 Jul 2025 09:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24330</strong></p>
  <p>Sending a crafted SOAP "provision" operation message PlanId field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later.  Beginning with release 24R1-SR 1.0 MP, the OAM se…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24330">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24329 – Sending a crafted SOAP "provision" operation message archive field within the Mo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24329</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24329</guid>
    <pubDate>Wed, 02 Jul 2025 09:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24329</strong></p>
  <p>Sending a crafted SOAP "provision" operation message archive field within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause path traversal issue in Nokia Single RAN baseband software with versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later.  Beginning with release 24R1-SR 1.0 MP, the OAM s…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24329">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-24328 – Sending a crafted SOAP "set" operation message within the Mobile Network Operato...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-24328</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-24328</guid>
    <pubDate>Wed, 02 Jul 2025 08:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-24328</strong></p>
  <p>Sending a crafted SOAP "set" operation message within the Mobile Network Operator (MNO) internal Radio Access Network (RAN) management network can cause Nokia Single RAN baseband OAM service component restart with software versions earlier than release 24R1-SR 1.0 MP. This issue has been corrected to release 24R1-SR 1.0 MP and later.  The OAM service component restarts automatically after the sta…</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-24328">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-21821 – In the Linux kernel, the following vulnerability has been resolved:

fbdev: omap...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-21821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-21821</guid>
    <pubDate>Thu, 27 Feb 2025 20:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-21821</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  fbdev: omap: use threaded IRQ for LCD DMA  When using touchscreen and framebuffer, Nokia 770 crashes easily with:      BUG: scheduling while atomic: irq/144-ads7846/82/0x00010000     Modules linked in: usb_f_ecm g_ether usb_f_rndis u_ether libcomposite configfs omap_udc ohci_omap ohci_hcd     CPU: 0 UID: 0 PID: 82 Comm: irq/144-…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-21821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-6729 – Nokia SR OS routers allow read-write access to the entire file system via SFTP o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6729</guid>
    <pubDate>Thu, 17 Oct 2024 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-6729</strong></p>
  <p>Nokia SR OS routers allow read-write access to the entire file system via SFTP or SCP for users configured with "access console." Consequently, a low privilege authenticated user with "access console" can read or replace the router configuration file as well as other files stored in the Compact Flash or SD card without using CLI commands. This type of attack can lead to a compromise or denial of…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-6728 – Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6728</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6728</guid>
    <pubDate>Thu, 17 Oct 2024 13:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-6728</strong></p>
  <p>Nokia SR OS bof.cfg file encryption is vulnerable to a brute force attack. This weakness allows an attacker in possession of the encrypted file to decrypt the bof.cfg file and obtain the BOF configuration content.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-326</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6728">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-25189 – BTS is affected by information disclosure vulnerability where mobile network ope...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25189</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25189</guid>
    <pubDate>Wed, 25 Sep 2024 16:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-25189</strong></p>
  <p>BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25189">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46743 – In the Linux kernel, the following vulnerability has been resolved:

of/irq: Pre...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46743</guid>
    <pubDate>Wed, 18 Sep 2024 08:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46743</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  of/irq: Prevent device address out-of-bounds read in interrupt map walk  When of_irq_parse_raw() is invoked with a device address smaller than the interrupt parent node (from #address-cells property), KASAN detects the following out-of-bounds read when populating the initial match table (dyndbg="func of_irq_parse_* +p"):    OF:…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38299 – Various software builds for the AT&amp;T Calypso, Nokia C100, Nokia C200, and BLU Vi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38299</guid>
    <pubDate>Mon, 22 Apr 2024 15:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38299</strong></p>
  <p>Various software builds for the AT&T Calypso, Nokia C100, Nokia C200, and BLU View 3 devices leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in these instances they are leaked by a hi…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38293 – Certain software builds for the Nokia C200 and Nokia C100 Android devices contai...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38293</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38293</guid>
    <pubDate>Mon, 22 Apr 2024 15:15:46 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38293</strong></p>
  <p>Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') that allows local third-party apps to execute arbitrary AT commands in its context (radio user) via AT command injection due to inadequate access control and inadequate input filtering. No permissions or…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38293">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-43675 – An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Eleme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43675</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43675</guid>
    <pubDate>Mon, 25 Dec 2023 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-43675</strong></p>
  <p>An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filename parameter, under /oms1350/pages/otn/connection/E2ERoutingDisplayWithOverLay via the id parameter, and under /oms1350/pages/otn/mainOtn via all parameters.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43675">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41762 – An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabili...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41762</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41762</guid>
    <pubDate>Mon, 25 Dec 2023 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41762</strong></p>
  <p>An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl, the bench or pid parameter to top.pl, or the id parameter to easy1350.pl.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41762">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41761 – An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41761</guid>
    <pubDate>Mon, 25 Dec 2023 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41761</strong></p>
  <p>An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI via the logfile parameter, allowing a remote authenticated attacker to read arbitrary files.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41760 – An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41760</guid>
    <pubDate>Mon, 25 Dec 2023 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41760</strong></p>
  <p>An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the filename parameter, allowing a remote authenticated attacker to read arbitrary files.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39822 – In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/eas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39822</guid>
    <pubDate>Mon, 25 Dec 2023 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39822</strong></p>
  <p>In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39820 – In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Crede...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39820</guid>
    <pubDate>Mon, 25 Dec 2023 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39820</strong></p>
  <p>In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges to the directory /root or /DEPOT, is able to read cleartext credentials to access the web portal NFM-T and control all t…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39818 – In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39818</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39818</guid>
    <pubDate>Mon, 25 Dec 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39818</strong></p>
  <p>In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39818">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41355 – Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input v...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41355</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41355</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41355</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-940</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41355">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-41354 – Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41354</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41354</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-41354</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41354">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41353 – Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirement...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41353</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41353</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41353</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41353">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41352 – Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41352</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41352</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41351 – Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41351</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41351</guid>
    <pubDate>Fri, 03 Nov 2023 06:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41351</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an administrator, to perform arbitrary system operations or disrupt service.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-288</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41351">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41350 – Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41350</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41350</guid>
    <pubDate>Fri, 03 Nov 2023 05:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41350</strong></p>
  <p>Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-307</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41350">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22618 – If Security Hardening guide rules are not followed, then Nokia WaveLite products...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22618</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22618</guid>
    <pubDate>Wed, 04 Oct 2023 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22618</strong></p>
  <p>If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite Metro 200 and F2B fans, WaveLite Metro 200 OPS and F2B fans, WaveLite Metro 200 NE and F2B fans, and WaveLite Metro 200…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22618">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-41763 – An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41763</guid>
    <pubDate>Tue, 05 Sep 2023 13:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-41763</strong></p>
  <p>An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41376 – Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-han...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41376</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41376</guid>
    <pubDate>Tue, 29 Aug 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41376</strong></p>
  <p>Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-670</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41376">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-30280 – /SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30280</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30280</guid>
    <pubDate>Mon, 24 Jul 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-30280</strong></p>
  <p>/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social engineering/phishing (such as sending a link via email or chat), an attacker may t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30280">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-28867 – An issue was discovered in Nokia NetAct 22 through the Administration of Measure...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28867</guid>
    <pubDate>Mon, 24 Jul 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-28867</strong></p>
  <p>An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed di…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-28865 – An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28865</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28865</guid>
    <pubDate>Mon, 24 Jul 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-28865</strong></p>
  <p>An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28865">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-28864 – An issue was discovered in Nokia NetAct 22 through the Administration of Measure...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28864</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28864</guid>
    <pubDate>Mon, 24 Jul 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-28864</strong></p>
  <p>An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim machine. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28864">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-28863 – An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28863</guid>
    <pubDate>Mon, 24 Jul 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-28863</strong></p>
  <p>An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25187 – An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. N...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25187</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25187</guid>
    <pubDate>Fri, 16 Jun 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25187</strong></p>
  <p>An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. Nokia Single RAN commissioning procedures do not change (factory-time installed) default SSH public/private key values that are specific to a network operator. As a result, the CSP internal BTS network SSH server (disabled by default) continues to apply the default SSH public/private key values. These keys don't give a…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25187">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25188 – An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25188</guid>
    <pubDate>Fri, 16 Jun 2023 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25188</strong></p>
  <p>An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from the Nokia Single RAN BTS baseband unit, the BTS baseband unit diagnostic tool AaShell (which is by default disabled) allows unauthenticated access from the mobile network solution internal BTS management network to the BTS embedded Linux operating-sy…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25186 – An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25186</guid>
    <pubDate>Fri, 16 Jun 2023 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25186</strong></p>
  <p>An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from a Nokia Single RAN BTS baseband unit, a directory path traversal in the Nokia BTS baseband unit diagnostic tool AaShell (which is by default disabled) provides access to the BTS baseband unit internal filesystem from the mobile network solution inter…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-25185 – An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25185</guid>
    <pubDate>Fri, 16 Jun 2023 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-25185</strong></p>
  <p>An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal software design have unnecessarily high privileges to BTS embedded operating system (OS) resources.</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-26062 – A mobile network solution internal fault is found in Nokia Web Element Manager b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26062</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26062</guid>
    <pubDate>Wed, 14 Jun 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-26062</strong></p>
  <p>A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that exploit is not possible from mobile network user UEs, from roaming networks, or from the Internet. Exploitation is possible…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26062">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-30759 – In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30759</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30759</guid>
    <pubDate>Tue, 02 May 2023 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-30759</strong></p>
  <p>In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and execute arbitrary commands.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30759">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-31244 – Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privile...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31244</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31244</guid>
    <pubDate>Tue, 25 Apr 2023 16:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-31244</strong></p>
  <p>Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31244">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26058 – An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26058</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26058</guid>
    <pubDate>Tue, 25 Apr 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26058</strong></p>
  <p>An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be pe…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26058">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26057 – An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26057</guid>
    <pubDate>Tue, 25 Apr 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26057</strong></p>
  <p>An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26059 – An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configurat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26059</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26059</guid>
    <pubDate>Mon, 24 Apr 2023 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26059</strong></p>
  <p>An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits Stored XSS. The upload option of the Site Configuration tool does not validate the file contents. The application is in a demilitarised zone behind a perimeter firewall and without exposure to the internet. The attack can only be performed b…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26059">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26061 – An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Searc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26061</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26061</guid>
    <pubDate>Mon, 24 Apr 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26061</strong></p>
  <p>An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard page, users can create a script to inject XSS. Input validation was missing during creation of a scheduled task. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token wou…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26061">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26060 – An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Man...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26060</guid>
    <pubDate>Mon, 24 Apr 2023 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26060</strong></p>
  <p>An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Set with a name that has a client-side template injection payload. Input validation is missing during creation of the working set. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2484 – The signature check in the Nokia ASIK AirScale system module version 474021A.101...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2484</guid>
    <pubDate>Fri, 06 Jan 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2484</strong></p>
  <p>The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary programs, or modified Nokia programs.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-1274</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2483 – The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2483</guid>
    <pubDate>Fri, 06 Jan 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2483</strong></p>
  <p>The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-1282</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-2482 – A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-2482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-2482</guid>
    <pubDate>Fri, 06 Jan 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-2482</strong></p>
  <p>A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-1274</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-2482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-36222 – Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a defaul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36222</guid>
    <pubDate>Wed, 21 Dec 2022 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-36222</strong></p>
  <p>Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-36221 – Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-36221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-36221</guid>
    <pubDate>Wed, 21 Dec 2022 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-36221</strong></p>
  <p>Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to read any named pipe file on the system.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-36221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-28866 – Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI &lt; ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28866</guid>
    <pubDate>Wed, 12 Oct 2022 00:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-28866</strong></p>
  <p>Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for access to (or editing of) data and functionality in all endpoints under /#settings/* and /api/settings/*. By not verifying the permissions for access to resources, it allows a potential attacker to view pages, with sensitive data, that are not allowed,…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-40715 – An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40715</guid>
    <pubDate>Mon, 19 Sep 2022 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-40715</strong></p>
  <p>An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-40714 – An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under diffe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40714</guid>
    <pubDate>Mon, 19 Sep 2022 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-40714</strong></p>
  <p>An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /oms1350/* endpoints.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-40713 – An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40713</guid>
    <pubDate>Mon, 19 Sep 2022 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-40713</strong></p>
  <p>An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-40712 – An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under diffe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-40712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-40712</guid>
    <pubDate>Mon, 19 Sep 2022 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-40712</strong></p>
  <p>An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-38788 – An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Blu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38788</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38788</guid>
    <pubDate>Thu, 15 Sep 2022 12:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-38788</strong></p>
  <p>An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38788">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39821 – In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Applicati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39821</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39821</strong></p>
  <p>In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39819 – In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39819</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39819</strong></p>
  <p>In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating system.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39819">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-39817 – In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploita...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39817</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-39817</strong></p>
  <p>In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39816 – In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext adminis...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39816</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39816</strong></p>
  <p>In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-39815 – In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39815</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-39815</strong></p>
  <p>In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-39814 – In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-39814</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-39814</guid>
    <pubDate>Tue, 13 Sep 2022 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-39814</strong></p>
  <p>In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-39814">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41487 – NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41487</guid>
    <pubDate>Thu, 16 Jun 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41487</strong></p>
  <p>NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-30903 – Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-30903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-30903</guid>
    <pubDate>Tue, 14 Jun 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-30903</strong></p>
  <p>Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-30903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-35487 – Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to pe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-35487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-35487</guid>
    <pubDate>Wed, 25 May 2022 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-35487</strong></p>
  <p>Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and database version information, and potentially database data.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-35487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-31932 – Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31932</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31932</guid>
    <pubDate>Fri, 11 Feb 2022 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-31932</strong></p>
  <p>Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31932">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-45896 – Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45896</guid>
    <pubDate>Mon, 27 Dec 2021 22:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-45896</strong></p>
  <p>Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-30003 – An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Store...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-30003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-30003</guid>
    <pubDate>Fri, 02 Apr 2021 05:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-30003</strong></p>
  <p>An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via urlfilter.cgi?add url_address.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-30003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26597 – An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26597</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26597</guid>
    <pubDate>Thu, 25 Mar 2021 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26597</strong></p>
  <p>An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26597">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-26596 – An issue was discovered in Nokia NetAct 18A. A malicious user can change a filen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-26596</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-26596</guid>
    <pubDate>Thu, 25 Mar 2021 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-26596</strong></p>
  <p>An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-26596">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-17406 – Nokia IMPACT &lt; 18A has path traversal that may lead to RCE if chained with CVE-2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17406</guid>
    <pubDate>Mon, 25 Nov 2019 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-17406</strong></p>
  <p>Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-17405 – Nokia IMPACT &lt; 18A: has Reflected self XSS</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17405</guid>
    <pubDate>Mon, 25 Nov 2019 15:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-17405</strong></p>
  <p>Nokia IMPACT < 18A: has Reflected self XSS</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-17404 – Nokia IMPACT &lt; 18A: allows full path disclosure</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17404</guid>
    <pubDate>Mon, 25 Nov 2019 15:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-17404</strong></p>
  <p>Nokia IMPACT < 18A: allows full path disclosure</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17403 – Nokia IMPACT &lt; 18A: An unrestricted File Upload vulnerability was found that may...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17403</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17403</guid>
    <pubDate>Mon, 25 Nov 2019 15:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17403</strong></p>
  <p>Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17403">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-7386 – A Denial of Service issue has been discovered in the Gecko component of KaiOS 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-7386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-7386</guid>
    <pubDate>Thu, 21 Mar 2019 16:01:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-7386</strong></p>
  <p>A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the internal browser, the Gecko process crashes with a segfault. Successful exploitation could lead to the remote code execution on the device.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-7386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-6929 – Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks (formerly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-6929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-6929</guid>
    <pubDate>Wed, 16 Sep 2015 18:59:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-6929</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in Nokia Networks (formerly Nokia Solutions and Networks and Nokia Siemens Networks) @vantage Commander allow remote attackers to inject arbitrary web script or HTML via the (1) idFilter or (2) nameFilter parameter to cftraces/filter/fl_copy.jsp; the (3) flName parameter to cftraces/filter/fl_crea1.jsp; the (4) serchStatus, (5) refreshTime, or (…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-6929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-1750 – Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps &amp; Places p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1750</guid>
    <pubDate>Wed, 01 Jul 2015 14:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-1750</strong></p>
  <p>Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the href parameter to page/place.html.  NOTE: this was originally reported as a cross-site scripting (XSS) vulnerability, but this may be inaccurate.</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-6602 – Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows phy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-6602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-6602</guid>
    <pubDate>Mon, 22 Sep 2014 01:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-6602</strong></p>
  <p>Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mechanism, and read or modify contact information or dial arbitrary telephone numbers, by tapping the SOS Option and then tapping the Green Call Option.</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-6602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-2619 – The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, As...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2619</guid>
    <pubDate>Wed, 14 Nov 2012 12:30:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-2619</strong></p>
  <p>The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung, and Sony products, allow remote attackers to cause a denial of service (out-of-bounds read and Wi-Fi outage) via an RSN 802.11i information element.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-2442 – Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-2442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-2442</guid>
    <pubDate>Wed, 25 Jul 2012 21:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-2442</strong></p>
  <p>Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial of service via a crafted mp4 file.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-2442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-1472 – The Nokia E75 phone with firmware before 211.12.01 allows physically proximate a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-1472</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-1472</guid>
    <pubDate>Tue, 29 Mar 2011 18:55:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-1472</strong></p>
  <p>The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-1472">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-0713 – Heap-based buffer overflow in wiretap/dct3trace.c in Wireshark 1.2.0 through 1.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0713</guid>
    <pubDate>Thu, 03 Mar 2011 01:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-0713</strong></p>
  <p>Heap-based buffer overflow in wiretap/dct3trace.c in Wireshark 1.2.0 through 1.2.14 and 1.4.0 through 1.4.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long record in a Nokia DCT3 trace file.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2011-0498 – Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-0498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-0498</guid>
    <pubDate>Thu, 20 Jan 2011 19:00:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2011-0498</strong></p>
  <p>Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long entry in a playlist (.npl) file.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-0498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-4549 – IBM Lotus Notes Traveler before 8.5.1.3 on the Nokia s60 device successfully per...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-4549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-4549</guid>
    <pubDate>Thu, 16 Dec 2010 20:00:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-4549</strong></p>
  <p>IBM Lotus Notes Traveler before 8.5.1.3 on the Nokia s60 device successfully performs a Replace Data operation for a prohibited application, which allows remote authenticated users to bypass intended access restrictions via this operation.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-4549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-5035 – The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-5035</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-5035</guid>
    <pubDate>Thu, 16 Dec 2010 20:00:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-5035</strong></p>
  <p>The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended messages.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-5035">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-2700 – src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2700</guid>
    <pubDate>Wed, 02 Sep 2009 17:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-2700</strong></p>
  <p>src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2009-2538 – The Nokia N95 running Symbian OS 9.2, N82, and N810 Internet Tablet allow remote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-2538</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-2538</guid>
    <pubDate>Mon, 20 Jul 2009 18:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2009-2538</strong></p>
  <p>The Nokia N95 running Symbian OS 9.2, N82, and N810 Internet Tablet allow remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-2538">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
