Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/165964/Nokia-Transport-Module-Authentication-Bypass.html | Exploit Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/165964/Nokia-Transport-Module-Authentication-Bypass.html | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:06
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/165964/Nokia-Transport-Module-Authentication-Bypass.html - Exploit, Third Party Advisory, VDB Entry |
Information
Published : 2022-02-11 18:15
Updated : 2024-11-21 06:06
NVD link : CVE-2021-31932
Mitre link : CVE-2021-31932
CVE.ORG link : CVE-2021-31932
JSON object : View
Products Affected
nokia
- bts_trs_web_console
CWE