PT-2022-10086 · Ericsson · Ericsson Network Manager
Alessandro Bosco
+2
·
Published
2022-08-25
·
Updated
2022-09-09
·
CVE-2021-32570
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ericsson Network Manager versions prior to 21.2
Description
The issue allows users belonging to the same AMOS authorization group to retrieve data from certain log files, potentially leading to privilege escalation. All AMOS users are considered highly privileged in the ENM system and must be previously defined and authorized by the Security Administrator. These users can access log files under a common path and read stored information to conduct privilege escalation.
Recommendations
For versions prior to 21.2, consider restricting access to log files under the common path to minimize the risk of exploitation. As a temporary workaround, limit the privileges of AMOS users to prevent them from accessing sensitive information in the log files. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ericsson Network Manager