CVE-2022-41763: Code Injection
An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41763?
CVE-2022-41763 is a vulnerability in NOKIA AMS 9.7.05 that allows remote code execution through the ipAddress variable debugger.
How severe is CVE-2022-41763?
CVE-2022-41763 has a severity score of 8.8, which is considered high.
How does CVE-2022-41763 work?
CVE-2022-41763 works by allowing a remote user, authenticated to the AMS server, to inject code in the PING function through the debugger of the ipAddress variable.
What software is affected by CVE-2022-41763?
CVE-2022-41763 affects NOKIA AMS 9.7.05.
How can CVE-2022-41763 be fixed?
To fix CVE-2022-41763, it is recommended to apply the latest security patches or updates provided by Nokia.