« Volver al listado

CVE-2025-24816

Estado: AnalizadaMedia (6.5)—

Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-24816",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-24816",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-30T13:30:08.532062Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "b48c3b8f-639e-4c16-8725-497bc411dad0",
      "affectedData": [
        {
          "vendor": "Nokia",
          "product": "MantaRay NM",
          "versions": [
            {
              "status": "affected",
              "version": "<25R2-NM"
            },
            {
              "status": "unaffected",
              "version": "≥25R2-NM"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-30T10:16:33.617",
  "references": [
    {
      "url": "https://www.nokia.com/we-are-nokia/security/product-security-advisory/cve-2025-24816/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "b48c3b8f-639e-4c16-8725-497bc411dad0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacker to retrieve confidential information beyond their assigned privileges."
    },
    {
      "lang": "es",
      "value": "Nokia MantaRay está sujeto a una vulnerabilidad de control de acceso inadecuado debido a una autorización insuficiente dentro de la API. La explotación exitosa podría permitir a un atacante autenticado recuperar información confidencial más allá de sus privilegios asignados."
    }
  ],
  "lastModified": "2026-09-29T19:10:00.160",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nokia:mantaray_nm:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B6443BC-E253-42E1-83CD-E681CBE3F6BE",
              "versionEndExcluding": "25R2-NM"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "b48c3b8f-639e-4c16-8725-497bc411dad0"
}