Improper Access Control Vulnerability in Nokia AirFrame BMC Web GUI
CVE-2022-28866
What is CVE-2022-28866?
The Nokia AirFrame BMC Web GUI contains multiple improper access control vulnerabilities that allow unauthorized users to bypass access controls and gain access to sensitive data and configurations. Specifically, the issues affect endpoints such as /#settings/* and /api/settings/*. Without proper validation of user permissions, attackers can not only view restricted pages but also modify system configurations, potentially leading to denial of service (DoS) conditions. This risk is particularly critical as it compromises confidentiality, integrity, and availability of the system, which should be reserved for users with administrative privileges.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved