8.8
CVSSv3

CVE-2022-39818

Published: 25/12/2023 Updated: 03/01/2024
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system.

Vulnerable Product Search on Vulmon Subscribe to Product

nokia network functions manager for transport 19.9