Ericsson
Ericsson Network Manager: vulnerabilidades y CVE
Ericsson Network Manager tiene 8 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-27259 | Baja (2.4) | 0.20% | — | 13 oct 2025 | Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims to other sites or domains. |
| CVE-2025-27258 | Media (6.9) | 0.30% | — | 13 oct 2025 | Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege. |
| CVE-2024-25007 | Alta (7.1) | 0.44% | — | 4 abr 2024 | Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or… |
| CVE-2023-39909 | Alta (8.8) | 0.78% | — | 7 dic 2023 | Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application. |
| CVE-2022-46408 | Media (6.8) | 0.92% | — | 29 jun 2023 | Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote… |
| CVE-2022-46407 | Media (4.8) | 0.35% | — | 29 jun 2023 | Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain… |
| CVE-2021-32570 | Media (4.9) | 0.76% | — | 26 ago 2022 | In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in… |
| CVE-2021-28488 | Media (6.5) | 1.1% | — | 10 mar 2022 | Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS… |
Otros productos de Ericsson
Codechecker · 10Packet Core Controller · 9Indoor Connect 8855 Firmware · 8Packet Core Gateway · 3Drutt Mobile Service Delivery Platform · 3Bscs IX R18 Billing & Rating MX · 2Operations Support System-radio AND Core Firmware · 2Enterprise Content Management · 2RAN Compute AND Site Controller 6610 · 2Bscs IX R18 Billing & Rating Admx · 2Evolved Packet Gateway · 1Active Library Explorer · 1