Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.17% | — | Nokia HIT 7300 Firmware | 30/9/2024 | 17/6/2026 | An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive password in firmware update packages allows attackers to access various appliance services via hardcoded credentials. | |
| Aplazada | Baja (3.3) | 0.13% | — | Nokia BTSAINokia BTS WEB Element ManagerAI | 25/9/2024 | 17/6/2026 | BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH. | |
| Aplazada | Media (5.5) | 0.17% | — | At&t CalypsoAINokia C100AINokia C200AIBLU View 3AI | 22/4/2024 | 17/6/2026 | Various software builds for the AT&T Calypso, Nokia C100, Nokia C200, and BLU View 3 devices leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device… | |
| Aplazada | Alta (7.3) | 0.78% | — | Nokia C200AINokia C100AITracfone TfstatusAI | 22/4/2024 | 17/6/2026 | Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') that allows local third-party apps to execute arbitrary AT commands in its context (radio user) via AT command injection… | |
| Modificada | Media (6.1) | 0.37% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. Reflected XSS in the Network Element Manager exists via /oms1350/pages/otn/cpbLogDisplay via the filename parameter, under /oms1350/pages/otn/connection/E2ERoutingDisplayWithOverLay via the id parameter, and under /oms1350/pages/otn/mainOtn via all parameters. | |
| Modificada | Media (6.1) | 0.37% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. Multiple Reflected XSS vulnerabilities exist in the Network Element Manager via any parameter to log.pl, the bench or pid parameter to top.pl, or the id parameter to easy1350.pl. | |
| Modificada | Media (6.5) | 0.80% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewlog.pl of the VM Manager WebUI via the logfile parameter, allowing a remote authenticated attacker to read arbitrary files. | |
| Modificada | Media (6.5) | 0.80% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Network Element Manager via the filename parameter, allowing a remote authenticated attacker to read arbitrary files. | |
| Modificada | Alta (8.8) | 0.62% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation. | |
| Modificada | Media (6.5) | 0.63% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges to the directory /root or /DEPOT, is… | |
| Modificada | Alta (8.8) | 2.2% | — | Nokia Network Functions Manager FOR Transport | 25/12/2023 | 17/6/2026 | In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parameter. This allows authenticated users to execute commands, with root privileges, on the operating system. | |
| Modificada | Crítica (9.8) | 0.62% | — | Nokia G-040w-q Firmware | 3/11/2023 | 17/6/2026 | Chunghwa Telecom NOKIA G-040W-Q Firewall function has a vulnerability of input validation for ICMP redirect messages. An unauthenticated remote attacker can exploit this vulnerability by sending a crafted package to modify the network routing table, resulting in a denial of service or sensitive information leaking. | |
| Modificada | Media (5.3) | 0.38% | — | Nokia G-040w-q Firmware | 3/11/2023 | 17/6/2026 | Chunghwa Telecom NOKIA G-040W-Q Firewall function does not block ICMP TIMESTAMP requests by default, an unauthenticated remote attacker can exploit this vulnerability by sending a crafted package, resulting in partially sensitive information exposed to an actor. | |
| Modificada | Alta (8.8) | 0.55% | — | Nokia G-040w-q Firmware | 3/11/2023 | 17/6/2026 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of weak password requirements. A remote attacker with regular user privilege can easily infer the administrator password from system information after logging system, resulting in admin access and performing arbitrary system operations or disrupt service. | |
| Modificada | Alta (7.2) | 1.2% | — | Nokia G-040w-q Firmware | 3/11/2023 | 17/6/2026 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient filtering for user input. A remote attacker with administrator privilege can exploit this vulnerability to perform a Command Injection attack to execute arbitrary commands, disrupt the system or terminate services. | |
| Modificada | Crítica (9.8) | 0.78% | — | Nokia G-040w-q Firmware | 3/11/2023 | 17/6/2026 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of authentication bypass, which allows an unauthenticated remote attacker to bypass the authentication mechanism to log in to the device by an alternative URL. This makes it possible for unauthenticated remote attackers to log in as any existing users, such as an… | |
| Modificada | Crítica (9.8) | 0.75% | — | Nokia G-040w-q Firmware | 3/11/2023 | 17/6/2026 | Chunghwa Telecom NOKIA G-040W-Q has a vulnerability of insufficient measures to prevent multiple failed authentication attempts. An unauthenticated remote attacker can execute a crafted Javascript to expose captcha in page, making it very easy for bots to bypass the captcha check and more susceptible to brute force… | |
| Modificada | Alta (7.8) | 0.16% | — | Nokia Wavelite Metro 200 AND FAN FirmwareNokia Wavelite Metro 200 OPS AND Fans FirmwareNokia Wavelite Metro 200 AND F2B Fans FirmwareNokia Wavelite Metro 200 OPS AND F2B Fans Firmware+2 | 4/10/2023 | 17/6/2026 | If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite Metro 200 and F2B fans, WaveLite Metro… | |
| Modificada | Alta (8.8) | 1.5% | — | Nokia Access Management System | 5/9/2023 | 17/6/2026 | An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service. | |
| Modificada | Alta (7.5) | 0.89% | — | Nokia Service Router LinuxNokia Service Router Operating System | 29/8/2023 | 17/6/2026 | Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes. | |
| Modificada | Alta (8.8) | 0.48% | — | Nokia Netact | 24/7/2023 | 17/6/2026 | /SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social… | |
| Modificada | Media (5.4) | 0.45% | — | Nokia Netact | 24/7/2023 | 17/6/2026 | An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content… | |
| Modificada | Media (5.4) | 0.45% | — | Nokia Netact | 24/7/2023 | 17/6/2026 | An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it… | |
| Modificada | Alta (8.8) | 1.0% | — | Nokia Netact | 24/7/2023 | 17/6/2026 | An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim machine. Here, the /aom/html/EditTemplate.jsf… | |
| Modificada | Alta (8.8) | 1.3% | — | Nokia Netact | 24/7/2023 | 17/6/2026 | An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value. |