Relative Path Traversal Vulnerability in Ericsson Mobile Switching Center Server
CVE-2021-28485
4.3MEDIUM
What is CVE-2021-28485?
A vulnerability in the Ericsson Mobile Switching Center Server (MSC-S) prior to IS 3.1 CP22 allows for relative path traversal through a specific parameter in HTTPS requests post-authentication. This flaw enables attackers to access sensitive files on the server that should remain protected from unauthorized web access, potentially leading to severe security breaches and data exposure.