Lucene search

K
cveMitreCVE-2022-28863
HistoryJul 24, 2023 - 2:15 p.m.

CVE-2022-28863

2023-07-2414:15:10
CWE-434
mitre
web.nvd.nist.gov
18
nokia
netact
cve-2022-28863
security
file upload
remote user
authentication
vulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

44.9%

An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.

Affected configurations

Nvd
Node
nokianetactMatch22.0.0.62
VendorProductVersionCPE
nokianetact22.0.0.62cpe:2.3:a:nokia:netact:22.0.0.62:*:*:*:*:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

44.9%

Related for CVE-2022-28863