CVE-2023-39909: High severity ericsson network manager vulnerability
Published Dec 7, 2023
·Updated
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.
Affected Software
1 affected component
Ericsson Network Manager<23.2
Event History
Dec 7, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-39909?
CVE-2023-39909 is classified as a high severity vulnerability due to its impact on access control.
2
How do I fix CVE-2023-39909?
To fix CVE-2023-39909, update the Ericsson Network Manager to version 23.2 or later.
3
What kind of access does CVE-2023-39909 allow to low-privilege users?
CVE-2023-39909 allows unauthenticated low-privilege users to access the NCM application improperly.
4
Which versions of Ericsson Network Manager are affected by CVE-2023-39909?
CVE-2023-39909 affects all versions of Ericsson Network Manager prior to 23.2.
5
Can CVE-2023-39909 lead to data breaches?
Yes, CVE-2023-39909 could potentially lead to unauthorized access to sensitive information.