CVE-2022-35503

Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the OSM components, retrieve confidential information, or gain access other parts of a Telco Operator infrastructure other than OSM itself.
Configurations

No configuration.

History

No history.

Information

Published : 2024-04-22 15:15

Updated : 2024-07-03 01:38


NVD link : CVE-2022-35503

Mitre link : CVE-2022-35503

CVE.ORG link : CVE-2022-35503


JSON object : View

Products Affected

No product.

CWE
CWE-286

Incorrect User Management

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')