Nokia / Netact
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-30280 | /SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrativ… | HIGH | 8.8 | Jul 24, 2023 |
| CVE-2022-28867 | An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parame… | MEDIUM | 5.4 | Jul 24, 2023 |
| CVE-2022-28865 | An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded file to i… | MEDIUM | 5.4 | Jul 24, 2023 |
| CVE-2022-28864 | An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parame… | HIGH | 8.8 | Jul 24, 2023 |
| CVE-2022-28863 | An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload p… | HIGH | 8.8 | Jul 24, 2023 |
| CVE-2023-26058 | An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML parser config… | MEDIUM | 6.5 | Apr 25, 2023 |
| CVE-2023-26057 | An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper XML parser… | MEDIUM | 6.5 | Apr 25, 2023 |
| CVE-2023-26061 | An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard page, users can create a script to inje… | MEDIUM | 6.8 | Apr 24, 2023 |
| CVE-2023-26060 | An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Set with a name that has a client-side te… | HIGH | 8.8 | Apr 24, 2023 |
| CVE-2023-26059 | An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a ZIP file which, when processed, exploits S… | MEDIUM | 6.8 | Apr 24, 2023 |
| CVE-2021-26596 | An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and ex… | MEDIUM | 5.4 | Mar 25, 2021 |
| CVE-2021-26597 | An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section… | MEDIUM | 6.5 | Mar 25, 2021 |
Showing 1 to 12 of 12 CVEs