Vulnerability Description
Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the OSM components, retrieve confidential information, or gain access other parts of a Telco Operator infrastructure other than OSM itself.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://osm.etsi.org/
- https://osm.etsi.org/news-events/blog/83-cve-2022-35503-disclosure
- https://osm.etsi.org/
- https://osm.etsi.org/news-events/blog/83-cve-2022-35503-disclosure
FAQ
What is CVE-2022-35503?
CVE-2022-35503 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descrip...
How severe is CVE-2022-35503?
CVE-2022-35503 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-35503?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.