Skip to main content

Vendor/product archive

ericsson / network_manager CVEs

Beta · best-effort

8 CVEs tagged to ericsson / network_manager0 Critical, 2 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2025-27259

Published Oct 13, 2025

Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites or domains.

CVSS 2.4 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-27258

Published Oct 13, 2025

Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.

CVSS 6.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-25007

Published Apr 4, 2024

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a C…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-39909

Published Dec 7, 2023

Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-46408

Published Jun 29, 2023

Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Ele…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46407

Published Jun 29, 2023

Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirecti…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32570

Published Aug 26, 2022

In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are consi…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28488

Published Mar 10, 2022

Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly priv…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1