PT-2023-14031 · Nokia · Nokia Nfm-T

Claudio Jacomelli

+2

·

Published

2023-12-25

·

Updated

2024-01-03

·

CVE-2022-41762

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions NOKIA NFM-T version R19.9
Description An issue was discovered in the Network Element Manager, where multiple Reflected XSS vulnerabilities exist. These vulnerabilities can be exploited via any parameter to log.pl, the bench or pid parameter to top.pl, or the id parameter to easy1350.pl.
Recommendations For NOKIA NFM-T version R19.9, consider disabling access to the vulnerable scripts log.pl, top.pl, and easy1350.pl until a patch is available. Restrict input parameters bench, pid, and id in the respective scripts to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-41762

Affected Products

Nokia Nfm-T