First published: Tue Oct 11 2022(Updated: )
Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for access to (or editing of) data and functionality in all endpoints under /#settings/* and /api/settings/*. By not verifying the permissions for access to resources, it allows a potential attacker to view pages, with sensitive data, that are not allowed, and modify system configurations also causing DoS, which should be accessed only by user with administration profile, bypassing all controls (without checking for user identity).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia Airframe Bmc Web Gui R18 Firmware | <4.13.00 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28866 is a vulnerability found in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00, which allows improper access control and does not properly validate requests for access to data and functionality in specific endpoints.
CVE-2022-28866 has a severity rating of 8.8 (high).
CVE-2022-28866 affects Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00 by allowing improper access control and lack of validation for access requests in certain endpoints.
CVE-2022-28866 is associated with CWE-862 (Missing Authorization).
Yes, you can find more information about CVE-2022-28866 at the following references: [link1], [link2].