Today > vulnerabilities   -   You can now download lists of IOCs here!

CVE-2022-35503

April 22, 2024, 7:24 p.m.

Tags

Product(s) Impacted

Open Source MANO

  • 7
  • 8
  • 9
  • 10
  • 11
  • 12

Open Source MANO

  • v7
  • v8
  • v9
  • v10
  • v11
  • v12

Description

Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the OSM components, retrieve confidential information, or gain access other parts of a Telco Operator infrastructure other than OSM itself.

Weaknesses

Date

Published: April 22, 2024, 3:15 p.m.

Last Modified: April 22, 2024, 7:24 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

cve@mitre.org

References

http://osm.com/ cve@mitre.org