CVE-2022-45899: OS Command Injection
Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-45899?
CVE-2022-45899 is classified as a critical severity vulnerability due to the potential for remote OS command injection by unauthenticated attackers.
How does CVE-2022-45899 affect systems?
CVE-2022-45899 allows attackers to execute arbitrary OS commands as root, compromising system integrity and control.
How do I fix CVE-2022-45899?
To mitigate CVE-2022-45899, upgrade the Nokia Broadcast Message Center software to version 13.1 or later, which addresses this vulnerability.
Who is affected by CVE-2022-45899?
Organizations using Nokia Broadcast Message Center (BMC) versions prior to 13.1 are affected by CVE-2022-45899.
Can CVE-2022-45899 be exploited remotely?
Yes, CVE-2022-45899 can be exploited remotely by unauthenticated attackers, making it particularly dangerous.