CVE-2021-32571

In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and passwords are left in the system undeleted but in folders accessible by top privileged accounts only. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Ericsson Network Manager is a new generation OSS system which OSS-RC customers shall upgrade to
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ericsson:operations_support_system-radio_and_core_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ericsson:operations_support_system-radio_and_core:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:35

Type Values Removed Values Added
Summary ** UNSUPPORTED WHEN ASSIGNED ** In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and passwords are left in the system undeleted but in folders accessible by top privileged accounts only. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Ericsson Network Manager is a new generation OSS system which OSS-RC customers shall upgrade to. In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and passwords are left in the system undeleted but in folders accessible by top privileged accounts only. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. Ericsson Network Manager is a new generation OSS system which OSS-RC customers shall upgrade to

20 Oct 2021, 19:31

Type Values Removed Values Added
CWE CWE-459
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.9
CPE cpe:2.3:o:ericsson:operations_support_system-radio_and_core_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:ericsson:operations_support_system-radio_and_core:-:*:*:*:*:*:*:*
References (MISC) https://www.gruppotim.it/it/innovazione/servizi-digitali/cybersecurity/red-team.html - (MISC) https://www.gruppotim.it/it/innovazione/servizi-digitali/cybersecurity/red-team.html - Third Party Advisory

14 Oct 2021, 18:58

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-14 18:15

Updated : 2024-04-11 01:11


NVD link : CVE-2021-32571

Mitre link : CVE-2021-32571

CVE.ORG link : CVE-2021-32571


JSON object : View

Products Affected

ericsson

  • operations_support_system-radio_and_core_firmware
  • operations_support_system-radio_and_core
CWE
CWE-459

Incomplete Cleanup