CVE-2022-21196
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.6.1 |
| Running on/with | Platform Versions |
|---|---|
Airspan C6x | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.6.1 |
| Running on/with | Platform Versions |
|---|---|
Airspan C5x | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.8.6.1 |
| Running on/with | Platform Versions |
|---|---|
Airspan C5c | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5.4.1 |
| Running on/with | Platform Versions |
|---|---|
Airspan A5x | All versions |
Related CWEs
CWE-285
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
CWE-287
Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
References (2)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.