CRITICAL🇵🇱 Wersja polska

CVE-2022-21196

CVSS 10.0v3.1pub. 2022-02-18upd. 2024-11-21

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Airspan A5x

    HW
    Airspan
    all versions
  • Airspan A5x Firmware

    OS
    Airspan
    < 2.5.4.1
  • Airspan C5c

    HW
    Airspan
    all versions
  • Airspan C5c Firmware

    OS
    Airspan
    < 2.8.6.1
  • Airspan C5x

    HW
    Airspan
    all versions
  • Airspan C5x Firmware

    OS
    Airspan
    < 2.8.6.1
  • Airspan C6x

    HW
    Airspan
    all versions
  • Airspan C6x Firmware

    OS
    Airspan
    < 2.8.6.1
  • Airspan Mimosa Management Platform

    APP
    Airspan
    < 1.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2022-21141CRITICAL10.0PL ✓same product

Brak autoryzacji API w urządzeniach Airspan — RCE i ujawnienie danych

CVE-2022-21215CRITICAL10.0PL ✓same product

SSRF w Airspan Mimosa Management Platform — dostęp do wewnętrznych API

CVE-2022-0138HIGH7.5same product

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x:...

CVE-2022-21143HIGH7.5same product

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x:...

CVE-2022-21176HIGH8.6same product

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x:...