Skip to content
Noroxi

Ericsson records

45 published records for vendor ericsson.

All records

45 records
  • CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.

    CriticalCVSS 10.0Proof of conceptEPSS 40%

    ericsson · codecheckerNov 6, 2024

  • In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export

    HighCVSS 8.8Proof of conceptEPSS 10%

    ericsson · network locationNov 3, 2021

  • Authentication bypass for certain API calls

    CriticalCVSS 9.3No exploitEPSS 1%

    ericsson · codecheckerApr 24, 2026

  • CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.

    CriticalCVSS 9.0No exploitEPSS 0%

    ericsson · codecheckerNov 6, 2024

  • An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to

    HighCVSS 8.8No exploitEPSS 1%

    ericsson · evolved packet gatewayDec 5, 2023

  • Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.

    HighCVSS 8.8No exploitEPSS 1%

    ericsson · network managerDec 7, 2023

  • Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command Vulnerability

    HighCVSS 8.5No exploitEPSS 1%

    ericsson · indoor connect 8855 firmwareSep 25, 2025

  • Ericsson Indoor Connect 8855 - Improper Input Validation Vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    ericsson · indoor connect 8855 firmwareSep 25, 2025

  • Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an SQL Command Vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    ericsson · indoor connect 8855 firmwareSep 25, 2025

  • Ericsson Indoor Connect 8855 - Missing Authorization Vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    ericsson · indoor connect 8855 firmwareSep 25, 2025

  • Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerability

    HighCVSS 8.5No exploitEPSS 0%

    ericsson · indoor connect 8855 firmwareMar 25, 2026

  • In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Inj

    HighCVSS 8.0No exploitEPSS 1%

    ericsson · enterprise content managementSep 17, 2021

  • Cross-Site Request Forgery in CodeChecker API

    HighCVSS 8.2No exploitEPSS 0%

    ericsson · codecheckerJan 21, 2025

  • CVE-2003-1442
    31Monitor

    The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain

    HighCVSS 7.5Proof of conceptEPSS 3%

    ericsson · hm220dp adsl modemDec 31, 2003

  • Buffer overflow in CodeChecker log command

    HighCVSS 7.8No exploitEPSS 0%

    ericsson · codecheckerOct 28, 2025

  • CVE-2015-2166
    28Monitor

    Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remot

    MediumCVSS 5.0Proof of conceptEPSS 27%

    ericsson · drutt mobile service delivery platformApr 6, 2015

  • Ericsson Network Manager - Improper Neutralization of Formula Elements Vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    ericsson · network managerApr 4, 2024

  • Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    ericsson · packet core gatewayJun 5, 2026

  • Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    ericsson · packet core gatewayJun 5, 2026

  • Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability

    HighCVSS 7.1No exploitEPSS 0%

    ericsson · packet core gatewayJun 5, 2026

  • Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerability

    HighCVSS 7.2No exploitEPSS 0%

    ericsson · indoor connect 8855 firmwareMar 25, 2026

  • Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially c

    HighCVSS 7.1No exploitEPSS 0%

    ericsson · packet core controllerJun 5, 2026

  • Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where

    MediumCVSS 6.8No exploitEPSS 1%

    ericsson · network managerJun 28, 2023

  • Ericsson Network Manager: escalation of privilege vulnerability

    MediumCVSS 6.9No exploitEPSS 0%

    ericsson · network managerOct 13, 2025

  • Ericsson RAN Compute and Site Controller 6610 - Improper Input Validation Vulnerability

    MediumCVSS 6.8No exploitEPSS 0%

    ericsson · ericsson ran compute basebands (all bb variants)Aug 16, 2024