MEDIUM · 4.3

CVE-2021-28485

In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which ...

Vulnerability Description

In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
EricssonMobile Switching Center Server Bc 18A Firmware>= is_3.1, < is_3.1_cp22
EricssonMobile Switching Center Server Bc 18A-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-28485?

CVE-2021-28485 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which ...

How severe is CVE-2021-28485?

CVE-2021-28485 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-28485?

Check the references section above for vendor advisories and patch information. Affected products include: Ericsson Mobile Switching Center Server Bc 18A Firmware, Ericsson Mobile Switching Center Server Bc 18A.