CVE-2022-21196
Estado: ModificadaCrítica (9.8)—
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.66%
- Percentil entre todas las CVEs puntuadas: 89
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (5)
CWE
- CWE-285
- CWE-287, NVD-CWE-Other
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-21196",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-21196",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-04-16T15:58:14.116430Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 10,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Airspan Networks",
"product": "MMP",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "v1.0.3",
"versionType": "custom"
}
]
},
{
"vendor": "Airspan Networks",
"product": "PTP C-series",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "v2.8.6.1",
"versionType": "custom"
}
]
},
{
"vendor": "Airspan Networks",
"product": "PTMP C-series and A5x",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "v2.5.4.1",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-02-18T18:15:12.527",
"references": [
{
"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-034-02",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-034-02",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-285"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
},
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information."
},
{
"lang": "es",
"value": "MMP: Todas las versiones anteriores a v1.0.3, PTP C-series: Versiones de dispositivos anteriores a v2.8.6.1, y PTMP C-series y A5x: Versiones de dispositivos anteriores a v2.5.4.1, no llevan a cabo las comprobaciones de autorización y autenticación apropiadas en varias rutas de la API. Un atacante puede obtener acceso a estas rutas API y lograr una ejecución de código remota, crear una condición de denegación de servicio y obtener información confidencial"
}
],
"lastModified": "2026-06-17T04:25:43.367",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:airspan:mimosa_management_platform:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "064DE49C-CD3C-43AF-864E-D8373EAD9B52",
"versionEndExcluding": "1.0.3"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:airspan:c6x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4650A7AA-DD66-4A8B-BB37-4D6789D60B85",
"versionEndExcluding": "2.8.6.1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:airspan:c6x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "080058F5-00C3-4204-8942-18D5347614B2"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:airspan:c5x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C295D0C-2C21-474D-B38F-0EA15FB59113",
"versionEndExcluding": "2.8.6.1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:airspan:c5x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2C3239C7-ADFF-413E-86CD-EDBD86FB1ACB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:airspan:c5c_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31B5039E-8D62-4EB8-A264-1DBA97CC7289",
"versionEndExcluding": "2.8.6.1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:airspan:c5c:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9944E65E-56D0-4010-B27B-FD7FE469EC20"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:airspan:a5x_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ECA42797-2BBB-4622-9F57-2BE53E3D8019",
"versionEndExcluding": "2.5.4.1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:airspan:a5x:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C1009C19-795D-4F1A-8C82-A22754E0EBC4"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}