CVE-2021-28485

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
14/09/2023
Last modified:
25/10/2023

Description

In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ericsson:mobile_switching_center_server_bc_18a_firmware:*:*:*:*:*:*:*:* is_3.1 (including) is_3.1_cp22 (excluding)
cpe:2.3:h:ericsson:mobile_switching_center_server_bc_18a:-:*:*:*:*:*:*:*