← Back

Nokia

nokia

146 CVEs • 110 products

Products (110)

Click to collapse
Toggle
Netact
netact
Impact
impact
Mantaray Nm
mantaray_nm
G42 Firmware
g42_firmware
Affix
affix
6131 Nfc
6131_nfc
Heif
heif
Wavesuite Noc
wavesuite_noc
N70
n70
Symbian
symbian
N95
n95
Impact Mobile
impact_mobile
6210 Handset
6210_handset
Sgsn Dx200
sgsn_dx200
Ipso
ipso
Ggsn
ggsn
6310i
Series
series
9500
3210
7610
Series 40
series_40
N82
n82
Nokia Pc Suite
nokia_pc_suite
Qtdemobrowser
qtdemobrowser
Qt Creator
qt_creator
E75 Firmware
e75_firmware
E75
e75
Pc Suite
pc_suite
Vitalsuite
vitalsuite
One Nds
one-nds
Infinera Dna
infinera_dna
S60
s60
8810 4g
8810_4g
G 120w F
g-120w-f
Fastmile
fastmile
G 2425g A
g-2425g-a
G 040w Q
g-040w-q
Hit 7300
hit_7300
808 Pureview
808_pureview
C7
c7
N8
n8

CVEs (146)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nokia
1Asika Airscale Firmware
Jun 17, 2026
Jun 16, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal soft...Show more
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. A mobile network solution internal fault was found in Nokia Single RAN software releases. Certain software processes in the BTS internal software design have unnecessarily high privileges to BTS embedded operating system (OS) resources.Show less
1Nokia
1Web Element Manager
Jun 17, 2026
Jun 14, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of...Show more
A mobile network solution internal fault is found in Nokia Web Element Manager before 22 R1, in which an authenticated, unprivileged user can execute administrative functions. Exploitation is not possible from outside of mobile network solution architecture. This means that exploit is not possible from mobile network user UEs, from roaming networks, or from the Internet. Exploitation is possible only from a CSP (Communication Service Provider) mobile network solution internal BTS management network.Show less
1Nokia
1One Nds
Jun 17, 2026
May 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and execute arbitrary commands.
1Nokia
1One Network Directory Server
Jun 17, 2026
Apr 25, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
1Nokia
1Netact
Jun 17, 2026
Apr 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very dif...Show more
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.Show less
1Nokia
1Netact
Jun 17, 2026
Apr 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is ve...Show more
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser configuration are missing. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.Show less
1Nokia
1Netact
Jun 17, 2026
Apr 24, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits Stored XSS. The upload option of the Site Configuration tool d...Show more
An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits Stored XSS. The upload option of the Site Configuration tool does not validate the file contents. The application is in a demilitarised zone behind a perimeter firewall and without exposure to the internet. The attack can only be performed by an internal user.Show less
1Nokia
1Netact
Jun 17, 2026
Apr 24, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard page, users can create a script to inject XSS. Input validation was missing during creation of a sch...Show more
An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard page, users can create a script to inject XSS. Input validation was missing during creation of a scheduled task. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.Show less
1Nokia
1Netact
Jun 17, 2026
Apr 24, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Set with a name that has a client-side template injection payload. Input validation is missing during...Show more
An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Set with a name that has a client-side template injection payload. Input validation is missing during creation of the working set. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.Show less
1Nokia
1Asik Airscale 474021a.101 Firmware
Jun 17, 2026
Jan 6, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary progr...Show more
The signature check in the Nokia ASIK AirScale system module version 474021A.101 can be bypassed allowing an attacker to run modified firmware. This could result in the execution of a malicious kernel, arbitrary programs, or modified Nokia programs. Show less
1Nokia
2Asik Airscale 474021a.101 Firmware
Asik Airscale 474021a.102 Firmware
Jun 17, 2026
Jan 6, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secur...Show more
The bootloader in the Nokia ASIK AirScale system module (versions 474021A.101 and 474021A.102) loads public keys for firmware verification signature. If an attacker modifies the flash contents to corrupt the keys, secure boot could be permanently disabled on a given device. Show less
1Nokia
2Asik Airscale 474021a.101 Firmware
Asik Airscale 474021a.102 Firmware
Jun 17, 2026
Jan 6, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the approp...Show more
A vulnerability exists in Nokia’s ASIK AirScale system module (versions 474021A.101 and 474021A.102) that could allow an attacker to place a script on the file system accessible from Linux. A script placed in the appropriate place could allow for arbitrary code execution in the bootloader. Show less
1Nokia
1Fastmile Firmware
Jun 17, 2026
Dec 21, 2022
N/A· v4
8.4 HIGH· v3
N/A· v2
Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin account of admin:Nq+L5st7o This account can be used locally to access the web admin interface.
1Nokia
1Fastmile Firmware
Jun 17, 2026
Dec 21, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to read any named pipe file on the system.
1Nokia
1Airframe Bmc Web Gui R18 Firmware
Jun 17, 2026
Oct 12, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for access to (or editing of) data and functionality in all endpoints under /#...Show more
Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for access to (or editing of) data and functionality in all endpoints under /#settings/* and /api/settings/*. By not verifying the permissions for access to resources, it allows a potential attacker to view pages, with sensitive data, that are not allowed, and modify system configurations also causing DoS, which should be accessed only by user with administration profile, bypassing all controls (without checking for user identity).Show less
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 19, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem...Show more
An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.Show less
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /oms1350/* endpoints.
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 19, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated attacker to read files on the filesyst...Show more
An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.Show less
1Nokia
11350 Optical Management System
Jun 17, 2026
Sep 19, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An issue was discovered in NOKIA 1350OMS R14.2. Reflected XSS exists under different /cgi-bin/R14.2* endpoints.
1Nokia
1Fastmile 5g Receiver Firmware
Jun 17, 2026
Sep 15, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline...Show more
An issue was discovered in Nokia FastMile 5G Receiver 5G14-B 1.2104.00.0281. Bluetooth on the Nokia ODU uses outdated pairing mechanisms, allowing an attacker to passively intercept a paring handshake and (after offline cracking) retrieve the PIN and LTK (long-term key).Show less