Airspan Networks Mimosa Incorrect Authorization
Published Feb 18, 2022
10.0
CRITICALCVSS 3.1
EPSS 3.16%
Description
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions. An attacker may gain access to these functions and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<v1.0.3
- Version
-
- Version unspecifiedStatusaffectedConstraints<v2.5.4.1
- Version
-
- Version unspecifiedStatusaffectedConstraints<v2.8.6.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Airspan Networks | MMP | n/a |
| ||||||
| Airspan Networks | PTMP C-series and A5x | n/a |
| ||||||
| Airspan Networks | PTP C-series | n/a |
|
Configuration 1
- < 1.0.3
Configuration 2
- < 2.8.6.1
Configuration 3
- < 2.8.6.1
Configuration 4
- < 2.8.6.1
Configuration 5
- < 2.5.4.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Airspan Networks recommends users update to following products (Login Required):
MMP: Version 1.0.4 or later PTP: C5x: Version 2.90 or later C5c: Version 2.90 or later PTMP: C-series: Version 2.9.0 or later A5x: Version 2.9.0 or later
References (1)
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-034-02 x_refsource_MISCThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-034-02 | x_refsource_MISCThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.