CVE-2022-35503

April 22, 2024, 7:24 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Open Source MANO

  • 7
  • 8
  • 9
  • 10
  • 11
  • 12

Open Source MANO

  • v7
  • v8
  • v9
  • v10
  • v11
  • v12

Source

cve@mitre.org

Tags

CVE-2022-35503 details

Published : April 22, 2024, 3:15 p.m.
Last Modified : April 22, 2024, 7:24 p.m.

Description

Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the OSM components, retrieve confidential information, or gain access other parts of a Telco Operator infrastructure other than OSM itself.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
This website uses the NVD API, but is not approved or certified by it.