PT-2022-23308 · Airspan · Airspan Airvelocity 1500

Published

2022-08-16

·

Updated

2022-08-17

·

CVE-2022-36312

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Airspan AirVelocity 1500 version 15.18.00.2511
Description The issue is related to a lack of CSRF protections in the eNodeB's web management UI. This may potentially affect other AirVelocity and AirSpeed models.
Recommendations For Airspan AirVelocity 1500 version 15.18.00.2511, consider disabling access to the web management UI until a patch is available to add CSRF protections. Restrict access to the eNodeB's web management UI to minimize the risk of exploitation.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-36312

Affected Products

Airspan Airvelocity 1500