Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41763


An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service.


Published

2023-09-05T13:15:07.717

Last Modified

2024-11-21T07:23:48.080

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nokia access_management_system 9.7.05 Yes

References