PT-2023-12128 · Ericsson · Ericsson Mobile Switching Center Server

Alessandro Bosco

+2

·

Published

2023-09-14

·

Updated

2023-10-25

·

CVE-2021-28485

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ericsson Mobile Switching Center Server (MSC-S) versions BC 18A and IS 3.1 through IS 3.1 CP21
Description The issue allows relative path traversal via a specific parameter in the https request after authentication, which enables access to files on the system that are not intended to be accessible via the web application.
Recommendations For Ericsson Mobile Switching Center Server (MSC-S) versions BC 18A and IS 3.1 through IS 3.1 CP21, update to IS 3.1 CP22 or later to resolve the issue.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2021-28485

Affected Products

Ericsson Mobile Switching Center Server