Remote Command Execution Vulnerability in Podman Container by Nokia
CVE-2023-49565

8.4HIGH

Key Information:

Vendor

Nokia

Status
Vendor
CVE Published:
18 September 2025

What is CVE-2023-49565?

The cbis_manager Podman container contains a vulnerability that allows for remote command execution through the /api/plugins endpoint. The issue stems from improper sanitization of the HTTP headers X-FILENAME, X-PAGE, and X-FIELD, which are leveraged directly in the subprocess.Popen function without sufficient validation. This oversight permits remote attackers to inject malicious header values into HTTP requests, leading to arbitrary command execution on the host system. Since the web service operates with root privileges within the container, successful exploitation can grant attackers elevated access. Implementing firewall restrictions on the management network can help reduce exposure to such threats.

Affected Version(s)

CBIS,NCS CBIS 22, NCS 22.12, NCS 23.10

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.