CVE-2021-28488: Medium severity ericsson network manager vulnerability
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-28488?
CVE-2021-28488 refers to a vulnerability in Ericsson Network Manager (ENM) before version 21.2 that causes incorrect access-control behavior.
How does CVE-2021-28488 impact users?
CVE-2021-28488 can allow users in the same AMOS authorization group to retrieve managed-network data that was supposed to be inaccessible.
How severe is CVE-2021-28488?
CVE-2021-28488 has a severity score of 6.5 out of 10, indicating a medium severity level.
Which version of Ericsson Network Manager is affected by CVE-2021-28488?
CVE-2021-28488 affects Ericsson Network Manager versions up to, but excluding, version 21.2.
Is there a fix available for CVE-2021-28488?
To address CVE-2021-28488, users should update to version 21.2 or a later version of Ericsson Network Manager.