CVE-2021-35486: CSRF
A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor the CSRF-NONCE cookie is validated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-35486?
CVE-2021-35486 has been classified as a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2021-35486?
To mitigate CVE-2021-35486, update Nokia IMPACT to version 19.11.2.11 or later where the CSRF protection mechanisms are properly implemented.
What is the impact of CVE-2021-35486?
CVE-2021-35486 allows remote attackers to import and overwrite the entire application configuration, compromising the integrity of the Nokia IMPACT application.
Which versions of Nokia IMPACT are affected by CVE-2021-35486?
Nokia IMPACT versions up to and including 19.11.2.10-20210118042150283 are affected by CVE-2021-35486.
How can I detect the exploitation of CVE-2021-35486?
Detection of CVE-2021-35486 exploitation can be challenging, but monitoring for unusual configuration changes and unauthorized imports can indicate potential attacks.