Data Leakage Vulnerability in OSS-RC Systems by Ericsson
CVE-2021-32571

4.9MEDIUM

Key Information:

Vendor

Ericsson

Vendor
CVE Published:
14 October 2021

What is CVE-2021-32571?

In OSS-RC systems, specifically in versions 18B and older, there exists a data leakage vulnerability during data migration procedures. This vulnerability allows certain files that contain sensitive information like usernames and passwords to remain undeleted in the system. These files may be stored in directories that are only accessible by accounts with top-level privileges. It's important to note that this vulnerability affects products that are no longer supported by the maintainer, which emphasizes the necessity for OSS-RC customers to upgrade to the newer Ericsson Network Manager for enhanced security.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.