CRITICAL🇵🇱 Wersja polska

CVE-2022-21215

CVSS 10.0v3.1pub. 2022-02-18upd. 2024-11-21

This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. The attacker could force the server into accessing routes on those cloud-hosting platforms, accessing secret keys, changing configurations, etc. Affecting MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Airspan A5x

    HW
    Airspan
    all versions
  • Airspan A5x Firmware

    OS
    Airspan
    < 2.5.4.1
  • Airspan C5c

    HW
    Airspan
    all versions
  • Airspan C5c Firmware

    OS
    Airspan
    < 2.8.6.1
  • Airspan C5x

    HW
    Airspan
    all versions
  • Airspan C5x Firmware

    OS
    Airspan
    < 2.8.6.1
  • Airspan C6x

    HW
    Airspan
    all versions
  • Airspan C6x Firmware

    OS
    Airspan
    < 2.8.6.1
  • Airspan Mimosa Management Platform

    APP
    Airspan
    < 1.0.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-21141CRITICAL10.0PL ✓same product

Brak autoryzacji API w urządzeniach Airspan — RCE i ujawnienie danych

CVE-2022-21196CRITICAL10.0PL ✓same product

Brak autoryzacji i uwierzytelnienia w API platformy Airspan — RCE

CVE-2022-0138HIGH7.5same product

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x:...

CVE-2022-21143HIGH7.5same product

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x:...

CVE-2022-21176HIGH8.6same product

MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x:...