ZeroHour

CVE-2021-28485

CVSS 3.1
4.3 medium
EPSS
<1%p44
Published
()
Modified
Description

In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.

Vendors
ericsson
Products
mobile switching center server bc 18a firmware
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.