In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.
References
Link | Resource |
---|---|
https://pentest.com.tr/blog/RCE-via-Meow-Variant-along-with-an-Example-0day-PacketHackingVillage-Defcon29.html | Exploit Third Party Advisory |
https://www.exploit-db.com/exploits/50468 | Exploit Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/50469 | Exploit Third Party Advisory VDB Entry |
Configurations
History
30 Nov 2021, 21:30
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.exploit-db.com/exploits/50469 - Exploit, Third Party Advisory, VDB Entry |
17 Nov 2021, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created. |
12 Nov 2021, 15:40
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ericsson:network_location:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 6.5
v3 : 8.8 |
Summary | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. |
05 Nov 2021, 17:57
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://www.exploit-db.com/exploits/50468 - Exploit, Third Party Advisory, VDB Entry | |
References | (MISC) https://pentest.com.tr/blog/RCE-via-Meow-Variant-along-with-an-Example-0day-PacketHackingVillage-Defcon29.html - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
CWE | CWE-77 | |
CPE | cpe:2.3:a:ericsson:network_location_mps_gmpc21:-:*:*:*:*:*:*:* |
03 Nov 2021, 20:24
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-11-03 20:15
Updated : 2024-02-04 22:08
NVD link : CVE-2021-43339
Mitre link : CVE-2021-43339
CVE.ORG link : CVE-2021-43339
JSON object : View
Products Affected
ericsson
- network_location
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')