CVE-2021-32570: Medium severity ericsson network manager vulnerability
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all must be previously defined and authorized by the Security Administrator. Those users can access some log’s files, under a common path, and read information stored in the log’s files in order to conduct privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32570?
CVE-2021-32570 is a vulnerability in Ericsson Network Manager (ENM) releases before version 21.2 that allows users belonging to the same AMOS authorization group to retrieve data from certain log files.
How severe is CVE-2021-32570?
CVE-2021-32570 has a severity rating of medium, with a severity value of 4.9.
How can users exploit CVE-2021-32570?
Users belonging to the same AMOS authorization group can exploit CVE-2021-32570 by retrieving data from certain log files in Ericsson Network Manager before version 21.2.
What is the affected software for CVE-2021-32570?
The affected software for CVE-2021-32570 is Ericsson Network Manager before version 21.2.
How can I fix CVE-2021-32570?
To fix CVE-2021-32570, users should upgrade to version 21.2 or newer of Ericsson Network Manager.