Insertion of Sensitive Information Vulnerability in NOKIA 1350 OMS
CVE-2022-39821

7.5HIGH

Key Information:

Vendor
Nokia
Vendor
CVE Published:
13 September 2022

Summary

In NOKIA 1350 OMS R14.2, there exists a vulnerability that allows sensitive information, including user credentials, to be stored in application log files. These log files are accessible in a world-readable state, potentially exposing critical information to unauthorized users. This security risk underscores the necessity of implementing robust access controls for log file handling to safeguard sensitive data from unauthorized access.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.