Show plain JSON{"id": "CVE-2021-28488", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 4.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N", "authentication": "SINGLE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 6.5, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 3.6, "exploitabilityScore": 2.8}]}, "published": "2022-03-10T17:42:08.193", "references": [{"url": "https://www.ericsson.com", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.ericsson.com/en/about-us/enterprise-security/psirt", "tags": ["Vendor Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.gruppotim.it/it/footer/red-team.html", "tags": ["Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://www.ericsson.com", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.ericsson.com/en/about-us/enterprise-security/psirt", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://www.gruppotim.it/it/footer/red-team.html", "tags": ["Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-668"}]}], "descriptions": [{"lang": "en", "value": "Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group)."}, {"lang": "es", "value": "Ericsson Network Manager (ENM) antes de la versi\u00f3n 21.2 tiene un comportamiento de control de acceso incorrecto (que s\u00f3lo afecta al nivel de acceso disponible para las personas a las que ya se les ha concedido un rol altamente privilegiado). Los usuarios del mismo grupo de autorizaci\u00f3n de AMOS pueden recuperar datos de la red gestionada que no estaban configurados para ser accesibles a todo el grupo (es decir, s\u00f3lo estaban configurados para ser accesibles a un subconjunto de ese grupo)"}], "lastModified": "2024-11-21T05:59:46.053", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:ericsson:network_manager:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "944DF153-84C6-4258-A87E-DB1143B21DE4", "versionEndExcluding": "21.2"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}