8.1
CWE
284
Advisory Published
Updated

CVE-2023-22618

First published: Wed Oct 04 2023(Updated: )

If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite Metro 200 and F2B fans, WaveLite Metro 200 OPS and F2B fans, WaveLite Metro 200 NE and F2B fans, and WaveLite Metro 200 NE OPS and F2B fans.

Credit: cve@mitre.org cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Nokia Wavelite Metro 200 And Fan Firmware<r2.1.1
Nokia Wavelite Metro 200 And Fan
Nokia Wavelite Metro 200 Ops And Fans Firmware<r2.1.1
Nokia Wavelite Metro 200 Ops And Fans
Nokia Wavelite Metro 200 And F2b Fans Firmware<r2.1.1
Nokia Wavelite Metro 200 And F2b Fans
Nokia Wavelite Metro 200 Ops And F2b Fans Firmware<r2.1.1
Nokia Wavelite Metro 200 Ops And F2b Fans
Nokia Wavelite Metro 200 Ne And F2b Fans Firmware<r2.1.1
Nokia Wavelite Metro 200 Ne And F2b Fans
Nokia Wavelite Metro 200 Ne Ops And F2b Fans Firmware<r2.1.1
Nokia Wavelite Metro 200 Ne Ops And F2b Fans
All of
Nokia Wavelite Metro 200 And Fan
Nokia Wavelite Metro 200 And Fan Firmware<r2.1.1
All of
Nokia Wavelite Metro 200 Ops And Fans
Nokia Wavelite Metro 200 Ops And Fans Firmware<r2.1.1
All of
Nokia Wavelite Metro 200 And F2b Fans
Nokia Wavelite Metro 200 And F2b Fans Firmware<r2.1.1
All of
Nokia Wavelite Metro 200 Ops And F2b Fans
Nokia Wavelite Metro 200 Ops And F2b Fans Firmware<r2.1.1
All of
Nokia Wavelite Metro 200 Ne And F2b Fans
Nokia Wavelite Metro 200 Ne And F2b Fans Firmware<r2.1.1
All of
Nokia Wavelite Metro 200 Ne Ops And F2b Fans
Nokia Wavelite Metro 200 Ne Ops And F2b Fans Firmware<r2.1.1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2023-22618?

    CVE-2023-22618 is a vulnerability that allows a local user to create new users with administrative privileges by manipulating a web request in Nokia WaveLite products if Security Hardening guide rules are not followed.

  • What is the severity of CVE-2023-22618?

    The severity of CVE-2023-22618 is high with a severity value of 7.8.

  • Which products are affected by CVE-2023-22618?

    Nokia WaveLite products including WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, and WaveLite Metro 200 and F2B fans are affected by CVE-2023-22618.

  • How can a local user exploit CVE-2023-22618?

    A local user can exploit CVE-2023-22618 by manipulating a web request to create new users with administrative privileges in Nokia WaveLite products.

  • Where can I find more information about CVE-2023-22618?

    You can find more information about CVE-2023-22618 on the official Nokia website and in the product security advisory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203