Vulnerability Description
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ericssonlg | Ipecs Nms | a.1ac |
Related Weaknesses (CWE)
References
- https://gist.github.com/berkgoksel/99ba5c1f3f9f6e4e33e7ad966c007693Third Party Advisory
- https://www.exploit-db.com/exploits/44515/Third Party AdvisoryVDB Entry
- https://gist.github.com/berkgoksel/99ba5c1f3f9f6e4e33e7ad966c007693Third Party Advisory
- https://www.exploit-db.com/exploits/44515/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2018-9245?
CVE-2018-9245 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating sy...
How severe is CVE-2018-9245?
CVE-2018-9245 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-9245?
Check the references section above for vendor advisories and patch information. Affected products include: Ericssonlg Ipecs Nms.