First published: Tue Sep 05 2023(Updated: )
An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nokia Access Management System | =9.7.05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41763 is a vulnerability in NOKIA AMS 9.7.05 that allows remote code execution through the ipAddress variable debugger.
CVE-2022-41763 has a severity score of 8.8, which is considered high.
CVE-2022-41763 works by allowing a remote user, authenticated to the AMS server, to inject code in the PING function through the debugger of the ipAddress variable.
CVE-2022-41763 affects NOKIA AMS 9.7.05.
To fix CVE-2022-41763, it is recommended to apply the latest security patches or updates provided by Nokia.