MEDIUM
An issue was discovered in Nokia NetAct 18A
Published Mar 25, 2021
5.4
MEDIUMCVSS 3.1
EPSS 0.74%
Description
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-13394 Advisory
- https://www.gruppotim.it/redteam x_refsource_MISCExploitThird Party Advisory
- https://www.trusted-introducer.org/directory/teams/nokia-psirt.html x_refsource_MISCThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-13394 | Advisory | |
| https://www.gruppotim.it/redteam | x_refsource_MISCExploitThird Party Advisory | |
| https://www.trusted-introducer.org/directory/teams/nokia-psirt.html | x_refsource_MISCThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 25, 2021
Updated Aug 3, 2024
Reserved Feb 2, 2021
Link CVE-2021-26596
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-13394 Assigner mitre
Published Mar 25, 2021
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2021-13394