CVE-2022-28863: Malicious File Upload
Published Jul 24, 2023
·Updated
An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.
Affected Software
1 affected component
Nokia NetAct=22.0.0.62
Event History
Jul 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-28863?
The severity of CVE-2022-28863 is high (8.8).
2
How does CVE-2022-28863 affect Nokia NetAct?
CVE-2022-28863 affects Nokia NetAct version 22.0.0.62.
3
What is the vulnerability type of CVE-2022-28863?
CVE-2022-28863 is a file upload vulnerability.
4
What are the potential consequences of CVE-2022-28863?
CVE-2022-28863 allows authenticated remote users to upload potentially dangerous files without restrictions.
5
Are there any solutions or mitigations available for CVE-2022-28863?
At the moment, there is no fix or patch available for CVE-2022-28863. It is recommended to keep the system up to date and follow vendor recommendations.