Nokia kayıtları
nokia üreticisine ait 153 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 17
- Düzeltme kaydı olan
- %9,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')10
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')10
- CWE-20 Improper Input Validation8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-312 Cleartext Storage of Sensitive Information5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
153 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2021-31932İstismar yok | Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass.nokia · bts trs web console | Kritik9,8 | — | %21,6 | 11 Şub 2022 |
44Planlayın | CVE-2005-2277Kavram kanıtı | Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters inokia · affix | Kritik10,0 | — | %12,9 | 15 Tem 2005 |
42Planlayın | CVE-2008-3553İstismar yok | Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vecnokia · series 40 · CWE-264 | Kritik10,0 | — | %5,9 | 8 Ağu 2008 |
42Planlayın | CVE-2008-3552İstismar yok | Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbitnokia · series 40 | Kritik10,0 | — | %5,9 | 8 Ağu 2008 |
41Planlayın | CVE-2019-3922İstismar yok | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST renokia · i-240w-q gpon ont firmware · CWE-121 | Kritik9,8 | — | %5,2 | 5 Mar 2019 |
40Planlayın | CVE-2019-3921Kavram kanıtı | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST renokia · i-240w-q gpon ont firmware · CWE-121 | Yüksek8,8 | — | %17,9 | 5 Mar 2019 |
40Planlayın | CVE-2022-39815İstismar yok | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.nokia · 1350 optical management system · CWE-78 | Kritik9,8 | — | %2,1 | 13 Eyl 2022 |
40Planlayın | CVE-2019-3918İstismar yok | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH inokia · i-240w-q gpon ont firmware · CWE-798 | Kritik9,8 | — | %2,0 | 5 Mar 2019 |
40Planlayın | CVE-2021-41487İstismar yok | NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.nokia · vitalsuite · CWE-89 | Kritik9,8 | — | %1,8 | 16 Haz 2022 |
39İzleyin | CVE-2011-0498Kavram kanıtı | Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to cnokia · multimedia player · CWE-119 | Kritik9,3 | — | %5,7 | 20 Oca 2011 |
39İzleyin | CVE-2009-0734Kavram kanıtı | Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code vnokia · nokia pc suite · CWE-119 | Kritik9,3 | — | %5,1 | 25 Şub 2009 |
39İzleyin | CVE-2023-41351İstismar yok | Chunghwa Telecom NOKIA G-040W-Q - Broken Access Controlnokia · g-040w-q firmware · CWE-288 | Kritik9,8 | — | %0,8 | 3 Kas 2023 |
39İzleyin | CVE-2023-41350İstismar yok | Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attemptsnokia · g-040w-q firmware · CWE-307 | Kritik9,8 | — | %0,8 | 3 Kas 2023 |
39İzleyin | CVE-2023-41355İstismar yok | Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validationnokia · g-040w-q firmware · CWE-940 | Kritik9,8 | — | %0,6 | 3 Kas 2023 |
39İzleyin | CVE-2025-27020İstismar yok | Improper configuration of SSH service in Infinera MTC-9nokia · infinera mtc-9 firmware · CWE-306 | Kritik9,8 | — | %0,5 | 8 Ara 2025 |
39İzleyin | CVE-2025-27019İstismar yok | Remote shell service (RSH) in Infinera MTC-9nokia · infinera mtc-9 firmware · CWE-306 | Kritik9,8 | — | %0,4 | 8 Ara 2025 |
36İzleyin | CVE-2019-3920İstismar yok | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTPnokia · i-240w-q gpon ont firmware · CWE-78 | Yüksek8,8 | — | %3,9 | 5 Mar 2019 |
36İzleyin | CVE-2019-3919İstismar yok | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent nokia · i-240w-q gpon ont firmware · CWE-78 | Yüksek8,8 | — | %3,9 | 5 Mar 2019 |
36İzleyin | CVE-2019-17403İstismar yok | Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.nokia · impact · CWE-434 | Yüksek8,8 | — | %2,5 | 25 Kas 2019 |
36İzleyin | CVE-2022-39818İstismar yok | In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parnokia · network functions manager for transport · CWE-78 | Yüksek8,8 | — | %2,2 | 25 Ara 2023 |
36İzleyin | CVE-2024-25660İstismar yok | The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthonokia · transcend network management system · CWE-266 | Kritik9,0 | — | %0,6 | 1 Eki 2024 |
36İzleyin | CVE-2025-24936İstismar yok | Insufficient Validation of Input in the URLnokia · wavesuite noc · CWE-78 | Kritik9,0 | — | %0,4 | 21 Tem 2025 |
36İzleyin | CVE-2025-24937İstismar yok | Access to local file system and its contentnokia · wavesuite noc · CWE-98 | Kritik9,0 | — | %0,2 | 21 Tem 2025 |
35İzleyin | CVE-2021-45896İstismar yok | Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use ofnokia · fastmile firmware | Yüksek8,8 | — | %1,6 | 27 Ara 2021 |
35İzleyin | CVE-2022-39819İstismar yok | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.nokia · 1350 optical management system · CWE-78 | Yüksek8,8 | — | %1,5 | 13 Eyl 2022 |
- CVE-2021-3193245Planlayın
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass.
KritikCVSS 9,8İstismar yokEPSS %22nokia · bts trs web console11 Şub 2022
- CVE-2005-227744Planlayın
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters i
KritikCVSS 10,0Kavram kanıtıEPSS %13nokia · affix15 Tem 2005
- CVE-2008-355342Planlayın
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vec
KritikCVSS 10,0İstismar yokEPSS %6nokia · series 408 Ağu 2008
- CVE-2008-355242Planlayın
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbit
KritikCVSS 10,0İstismar yokEPSS %6nokia · series 408 Ağu 2008
- CVE-2019-392241Planlayın
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST re
KritikCVSS 9,8İstismar yokEPSS %5nokia · i-240w-q gpon ont firmware5 Mar 2019
- CVE-2019-392140Planlayın
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST re
YüksekCVSS 8,8Kavram kanıtıEPSS %18nokia · i-240w-q gpon ont firmware5 Mar 2019
- CVE-2022-3981540Planlayın
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.
KritikCVSS 9,8İstismar yokEPSS %2nokia · 1350 optical management system13 Eyl 2022
- CVE-2019-391840Planlayın
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH i
KritikCVSS 9,8İstismar yokEPSS %2nokia · i-240w-q gpon ont firmware5 Mar 2019
- CVE-2021-4148740Planlayın
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
KritikCVSS 9,8İstismar yokEPSS %2nokia · vitalsuite16 Haz 2022
- CVE-2011-049839İzleyin
Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to c
KritikCVSS 9,3Kavram kanıtıEPSS %6nokia · multimedia player20 Oca 2011
- CVE-2009-073439İzleyin
Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code v
KritikCVSS 9,3Kavram kanıtıEPSS %5nokia · nokia pc suite25 Şub 2009
- CVE-2023-4135139İzleyin
Chunghwa Telecom NOKIA G-040W-Q - Broken Access Control
KritikCVSS 9,8İstismar yokEPSS %1nokia · g-040w-q firmware3 Kas 2023
- CVE-2023-4135039İzleyin
Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attempts
KritikCVSS 9,8İstismar yokEPSS %1nokia · g-040w-q firmware3 Kas 2023
- CVE-2023-4135539İzleyin
Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validation
KritikCVSS 9,8İstismar yokEPSS %1nokia · g-040w-q firmware3 Kas 2023
- CVE-2025-2702039İzleyin
Improper configuration of SSH service in Infinera MTC-9
KritikCVSS 9,8İstismar yokEPSS %1nokia · infinera mtc-9 firmware8 Ara 2025
- CVE-2025-2701939İzleyin
Remote shell service (RSH) in Infinera MTC-9
KritikCVSS 9,8İstismar yokEPSS %0nokia · infinera mtc-9 firmware8 Ara 2025
- CVE-2019-392036İzleyin
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP
YüksekCVSS 8,8İstismar yokEPSS %4nokia · i-240w-q gpon ont firmware5 Mar 2019
- CVE-2019-391936İzleyin
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent
YüksekCVSS 8,8İstismar yokEPSS %4nokia · i-240w-q gpon ont firmware5 Mar 2019
- CVE-2019-1740336İzleyin
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
YüksekCVSS 8,8İstismar yokEPSS %3nokia · impact25 Kas 2019
- CVE-2022-3981836İzleyin
In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET par
YüksekCVSS 8,8İstismar yokEPSS %2nokia · network functions manager for transport25 Ara 2023
- CVE-2024-2566036İzleyin
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unautho
KritikCVSS 9,0İstismar yokEPSS %1nokia · transcend network management system1 Eki 2024
- CVE-2025-2493636İzleyin
Insufficient Validation of Input in the URL
KritikCVSS 9,0İstismar yokEPSS %0nokia · wavesuite noc21 Tem 2025
- CVE-2025-2493736İzleyin
Access to local file system and its content
KritikCVSS 9,0İstismar yokEPSS %0nokia · wavesuite noc21 Tem 2025
- CVE-2021-4589635İzleyin
Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of
YüksekCVSS 8,8İstismar yokEPSS %2nokia · fastmile firmware27 Ara 2021
- CVE-2022-3981935İzleyin
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.
YüksekCVSS 8,8İstismar yokEPSS %1nokia · 1350 optical management system13 Eyl 2022