CVE-2022-39816

In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker.
References
Link Resource
https://www.gruppotim.it/it/footer/red-team.html Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:nokia:1350_optical_management_system:14.2:*:*:*:*:*:*:*

History

23 Sep 2022, 12:15

Type Values Removed Values Added
Summary In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext password) occur in /cgi-bin/R14.2/cgi-bin/R14.2/host.pl on the edit configuration page. Exploitation requires an authenticated attacker. In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker.

16 Sep 2022, 19:39

Type Values Removed Values Added
First Time Nokia 1350 Optical Management System
Nokia
CWE CWE-522
References (MISC) https://www.gruppotim.it/it/footer/red-team.html - (MISC) https://www.gruppotim.it/it/footer/red-team.html - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:nokia:1350_optical_management_system:14.2:*:*:*:*:*:*:*

13 Sep 2022, 21:27

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-13 21:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-39816

Mitre link : CVE-2022-39816

CVE.ORG link : CVE-2022-39816


JSON object : View

Products Affected

nokia

  • 1350_optical_management_system
CWE
CWE-522

Insufficiently Protected Credentials