CVE-2022-21176

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input, which may allow an attacker to perform a SQL injection and obtain sensitive information.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-034-02 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:airspan:mimosa_management_platform:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:airspan:c6x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:airspan:c6x:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:airspan:c5x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:airspan:c5x:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:airspan:c5c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:airspan:c5c:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:airspan:a5x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:airspan:a5x:-:*:*:*:*:*:*:*

History

26 Feb 2022, 04:52

Type Values Removed Values Added
First Time Airspan c5x Firmware
Airspan c6x Firmware
Airspan c6x
Airspan mimosa Management Platform
Airspan
Airspan a5x Firmware
Airspan c5x
Airspan c5c Firmware
Airspan c5c
Airspan a5x
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
References (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-034-02 - (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-034-02 - Third Party Advisory, US Government Resource
CPE cpe:2.3:o:airspan:c5x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:airspan:a5x:-:*:*:*:*:*:*:*
cpe:2.3:h:airspan:c5x:-:*:*:*:*:*:*:*
cpe:2.3:o:airspan:a5x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:airspan:c5c:-:*:*:*:*:*:*:*
cpe:2.3:a:airspan:mimosa_management_platform:*:*:*:*:*:*:*:*
cpe:2.3:o:airspan:c5c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:airspan:c6x:-:*:*:*:*:*:*:*
cpe:2.3:o:airspan:c6x_firmware:*:*:*:*:*:*:*:*

18 Feb 2022, 18:33

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-18 18:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-21176

Mitre link : CVE-2022-21176

CVE.ORG link : CVE-2022-21176


JSON object : View

Products Affected

airspan

  • a5x_firmware
  • c5c_firmware
  • c5c
  • mimosa_management_platform
  • c6x_firmware
  • c5x
  • a5x
  • c6x
  • c5x_firmware
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')