CVE-2021-43339: Command Injection
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via filename in the export functionality. For example, a new admin user could be created.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-43339?
CVE-2021-43339 is a vulnerability in Ericsson Network Location that allows an authenticated attacker to inject commands via the file_name parameter in the export functionality.
How severe is CVE-2021-43339?
CVE-2021-43339 has a severity rating of 8.8, which is considered high.
How can an attacker exploit CVE-2021-43339?
An attacker can exploit CVE-2021-43339 by injecting commands via the file_name parameter in the export functionality.
Is there a fix available for CVE-2021-43339?
As of July 31, 2021, a fix for CVE-2021-43339 is not available. It is recommended to follow the vendor's security advisories for updates and patches.
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-43339?
The CWE ID for CVE-2021-43339 is CWE-77, which is for Improper Neutralization of Special Elements used in a Command ('Command Injection').