Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-28485


In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.


Published

2023-09-14T15:15:07.827

Last Modified

2024-11-21T05:59:45.883

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ericsson mobile_switching_center_server_bc_18a_firmware < is_3.1_cp22 Yes
Hardware ericsson mobile_switching_center_server_bc_18a - No

References