CVE-2023-31044: Code Injection

Published Mar 3, 2026
·
Updated

An issue was discovered in Nokia Impact before Mobile 23FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported to a CSV file. Attackers can populate data fields that may attempt data exfiltration or other malicious activity when automatically executed by the spreadsheet software.

Affected Software

3 affected components
Nokia IMPACT<Mobile 23_FP1
Nokia Impact DM>=undefined
Nokia Impact Mobile>=19.11<=23

Event History

Mar 3, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Mar 21, 58156
Event
via NVD·01:33 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-31044?

CVE-2023-31044 has a moderate severity level due to its potential for remote code execution via payload injection.

2

How do I fix CVE-2023-31044?

To fix CVE-2023-31044, upgrade to Nokia Impact Mobile version 23_FP1 or later to ensure the vulnerability is resolved.

3

Who is affected by CVE-2023-31044?

CVE-2023-31044 affects users of Nokia Impact and Impact DM versions prior to Mobile 23_FP1.

4

What type of vulnerability is CVE-2023-31044?

CVE-2023-31044 is a remote code execution vulnerability due to improper handling of input in the Campaign Name field.

5

Can CVE-2023-31044 be exploited without user authentication?

No, exploiting CVE-2023-31044 requires a remote authenticated user to take action using the Add Campaign functionality.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203