CVE-2022-40715

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
19/09/2022
Last modified:
21/09/2022

Description

An issue was discovered in NOKIA 1350OMS R14.2. An Absolute Path Traversal vulnerability exists for a specific endpoint via the logfile parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nokia:1350_optical_management_system:14.2:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools