In Network Element Manager in NOKIA NFM-T R19.9, an...
Moderate severity
Unreviewed
Published
Dec 25, 2023
to the GitHub Advisory Database
•
Updated Jan 12, 2024
Description
Published by the National Vulnerability Database
Dec 25, 2023
Published to the GitHub Advisory Database
Dec 25, 2023
Last updated
Jan 12, 2024
In Network Element Manager in NOKIA NFM-T R19.9, an Unprotected Storage of Credentials vulnerability occurs under /root/RestUploadManager.xml.DRC and /DEPOT/KECustom_199/OTNE_DRC/RestUploadManager.xml. A remote user, authenticated to the operating system, with access privileges to the directory /root or /DEPOT, is able to read cleartext credentials to access the web portal NFM-T and control all the PPS Network elements.
References