Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
nokia vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv3
CVE-2022-39816
In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker.
Nokia 1350 Optical Management System 14.2
8.8
CVSSv3
CVE-2022-39819
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This allows authenticated users to execute commands on the operating system.
Nokia 1350 Optical Management System 14.2
7.5
CVSSv3
CVE-2022-39821
In NOKIA 1350 OMS R14.2, an Insertion of Sensitive Information into an Application Log File vulnerability occurs. The web application stores critical information, such as cleartext user credentials, in world-readable files in the filesystem.
Nokia 1350 Optical Management System 14.2
6.1
CVSSv3
CVE-2022-40712
An issue exists in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.
Nokia 1350 Optical Management System 14.2
6.5
CVSSv3
CVE-2022-40713
An issue exists in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated malicious user to read files on the filesystem arbitrarily.
Nokia 1350 Optical Management System 14.2
6.1
CVSSv3
CVE-2022-40714
An issue exists in NOKIA 1350OMS R14.2. Reflected XSS exists under different /oms1350/* endpoints.
Nokia 1350 Optical Management System 14.2
6.5
CVSSv3
CVE-2022-40715
An issue exists in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated malicious user to read files on the filesystem arbitrarily.
Nokia 1350 Optical Management System 14.2
9.8
CVSSv3
CVE-2021-31932
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.
Nokia Bts Trs Web Console Ftm W20 Fp2 2019.08.16 0010
6.1
CVSSv3
CVE-2022-39814
In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.
Nokia 1350 Optical Management System 14.2
9.8
CVSSv3
CVE-2022-39815
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.
Nokia 1350 Optical Management System 14.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
6
7
8
9
10
NEXT »