← Back

CVE-2022-21215

nvd nist
Published: Feb 18, 2022Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. The attacker could force the server into accessing routes on those cloud-hosting platforms, accessing secret keys, changing configurations, etc. Affecting MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1.

Affected (5)

5 products
Mimosa Management Platform
C6x Firmware
C5x Firmware
C5c Firmware
A5x Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.0.3
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.8.6.1
Running on/withPlatform Versions
Airspan
C6x
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.8.6.1
Running on/withPlatform Versions
Airspan
C5x
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.8.6.1
Running on/withPlatform Versions
Airspan
C5c
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.5.4.1
Running on/withPlatform Versions
Airspan
A5x
All versions

References (2)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.