CVE-2021-28488
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).
Ericsson Network Manager (ENM) antes de la versión 21.2 tiene un comportamiento de control de acceso incorrecto (que sólo afecta al nivel de acceso disponible para las personas a las que ya se les ha concedido un rol altamente privilegiado). Los usuarios del mismo grupo de autorización de AMOS pueden recuperar datos de la red gestionada que no estaban configurados para ser accesibles a todo el grupo (es decir, sólo estaban configurados para ser accesibles a un subconjunto de ese grupo)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-16 CVE Reserved
- 2022-03-08 CVE Published
- 2024-01-23 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-668: Exposure of Resource to Wrong Sphere
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.gruppotim.it/it/footer/red-team.html | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ericsson.com | 2022-07-12 | |
https://www.ericsson.com/en/about-us/enterprise-security/psirt | 2022-07-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ericsson Search vendor "Ericsson" | Network Manager Search vendor "Ericsson" for product "Network Manager" | < 21.2 Search vendor "Ericsson" for product "Network Manager" and version " < 21.2" | - |
Affected
|