PT-2020-17099 · Ericsson · Ericsson Bscs Ix

Aamir Rehman

·

Published

2020-11-27

·

Updated

2020-12-04

·

CVE-2020-29144

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ericsson BSCS iX R18 Billing & Rating iX R18
Description The issue concerns a stored XSS vulnerability in the MX web-based module of Ericsson BSCS iX, specifically via an Alert Dashboard comment. This vulnerability can potentially lead to session hijacking, allowing for full account takeover. Additionally, it may enable exploiting admins' browsers using the beef framework.
Recommendations For Ericsson BSCS iX R18 Billing & Rating iX R18, consider disabling the Alert Dashboard comment feature in the MX module until a patch is available to prevent exploitation of the stored XSS vulnerability. Restrict access to the MX module to minimize the risk of session hijacking and subsequent account takeover. Avoid using the Alert Dashboard comment feature in the affected module until the issue is resolved.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29144

Affected Products

Ericsson Bscs Ix