Absolute Path Traversal Vulnerability in NOKIA NFM-T WebUI
CVE-2022-41761
6.5MEDIUM
Summary
A vulnerability in NOKIA NFM-T R19.9 allows an authenticated remote attacker to exploit an Absolute Path Traversal under the VM Manager WebUI path /cgi-bin/R19.9/viewlog.pl. By manipulating the logfile parameter, the attacker can gain unauthorized access to arbitrary files on the server, potentially exposing sensitive information and compromising the system's integrity.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved