Skip to main content

Vendor archive

ericsson CVEs

Beta · best-effort

44 CVEs tagged to vendor ericsson2 Critical, 18 High, 23 Medium, 1 Low, 0 Unrated.

CVE-2022-46408

Published Jun 29, 2023

Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Ele…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46407

Published Jun 29, 2023

Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirecti…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32570

Published Aug 26, 2022

In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are consi…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28488

Published Mar 10, 2022

Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly priv…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-44217

Published Jan 18, 2022

In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of the reports viewer allows remote attackers to inject arbitra…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43339

Published Nov 3, 2021

In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41391

Published Sep 17, 2021

In Ericsson ECM before 18.0, it was observed that Security Management Endpoint in User Profile Management Section is vulnerable to stored XSS via a name, leading to session hijack…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7417

Published Mar 21, 2019

XSS exists in Ericsson Active Library Explorer (ALEX) 14.3 in multiple parameters in the "/cgi-bin/alexserv" servlet, as demonstrated by the DB, FN, fn, or id parameter.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2167

Published Apr 6, 2015

Open redirect vulnerability in the 3PI Manager in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to redirect users to arbitrary web sit…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1442

Published Dec 31, 2003

The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain access from the LAN side.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0542

Published Jun 13, 2000

Tigris remote access server before 11.5.4.22 does not properly record Radius accounting information when a user fails the initial login authentication but subsequently succeeds.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-44 of 44 CVEsPage 2 of 2