PT-2022-7169 · Ericsson · Ericsson Evolved Packet Gateway
Andrea Carlo Maria Dattola
+2
·
Published
2022-12-19
·
Updated
2023-12-11
·
CVE-2022-47531
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ericsson Evolved Packet Gateway (EPG) versions 2.x before 2.16
Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25
Description
The issue is related to the command-line interface (CLI) of the Ericsson Evolved Packet Gateway (EPG) and is associated with access control deficiencies. Exploitation of the issue may allow a remote attacker to execute arbitrary commands. Authenticated users can bypass the system CLI and execute commands they are authorized to execute directly in the UNIX shell.
Recommendations
For Ericsson Evolved Packet Gateway (EPG) versions 2.x before 2.16, update to version 2.16 or later to resolve the issue.
For Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25, update to version 3.25 or later to resolve the issue.
As a temporary workaround, consider restricting access to the CLI to minimize the risk of exploitation.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ericsson Evolved Packet Gateway