PT-2023-12953 · Nokia · Nokia Netact
Andrea Carlo Maria Dattola
+2
·
Published
2023-07-24
·
Updated
2023-08-02
·
CVE-2022-28863
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nokia NetAct version 22
Description
A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the "/netact/sct" dir parameter in conjunction with the
operation=upload value.Recommendations
For Nokia NetAct version 22, restrict access to the "/netact/sct" endpoint to prevent arbitrary file uploads until a patch is available. As a temporary workaround, consider disabling the file upload functionality in the Site Configuration Tool section to minimize the risk of exploitation.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nokia Netact