Записи Ericsson
45 опубликованных записей вендора ericsson.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 51,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-228 Improper Handling of Syntactically Invalid Structure3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-230 Improper Handling of Missing Values2
- CWE-20 Improper Input Validation2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
45 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
52В плане | CVE-2024-10081Proof of concept | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.ericsson · codechecker · CWE-288 | Критическая10,0 | — | 39,9 % | 6 нояб. 2024 г. |
38Наблюдать | CVE-2021-43339Proof of concept | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export ericsson · network location · CWE-77 | Высокая8,8 | — | 9,6 % | 3 нояб. 2021 г. |
37Наблюдать | CVE-2026-25660Эксплойта нет | Authentication bypass for certain API callsericsson · codechecker · CWE-290 | Критическая9,3 | — | 0,6 % | 24 апр. 2026 г. |
36Наблюдать | CVE-2024-10082Эксплойта нет | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.ericsson · codechecker · CWE-305 | Критическая9,0 | — | 0,5 % | 6 нояб. 2024 г. |
35Наблюдать | CVE-2022-47531Эксплойта нет | An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users toericsson · evolved packet gateway | Высокая8,8 | — | 1,0 % | 5 дек. 2023 г. |
35Наблюдать | CVE-2023-39909Эксплойта нет | Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.ericsson · network manager | Высокая8,8 | — | 0,8 % | 7 дек. 2023 г. |
34Наблюдать | CVE-2025-27262Эксплойта нет | Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command Vulnerabilityericsson · indoor connect 8855 firmware · CWE-78 | Высокая8,5 | — | 0,7 % | 25 сент. 2025 г. |
34Наблюдать | CVE-2025-40836Эксплойта нет | Ericsson Indoor Connect 8855 - Improper Input Validation Vulnerabilityericsson · indoor connect 8855 firmware · CWE-20 | Высокая8,7 | — | 0,4 % | 25 сент. 2025 г. |
34Наблюдать | CVE-2025-27261Эксплойта нет | Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an SQL Command Vulnerabilityericsson · indoor connect 8855 firmware · CWE-89 | Высокая8,7 | — | 0,3 % | 25 сент. 2025 г. |
34Наблюдать | CVE-2025-40837Эксплойта нет | Ericsson Indoor Connect 8855 - Missing Authorization Vulnerabilityericsson · indoor connect 8855 firmware · CWE-862 | Высокая8,7 | — | 0,3 % | 25 сент. 2025 г. |
34Наблюдать | CVE-2025-40842Эксплойта нет | Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerabilityericsson · indoor connect 8855 firmware · CWE-79 | Высокая8,5 | — | 0,1 % | 25 мар. 2026 г. |
32Наблюдать | CVE-2021-41390Эксплойта нет | In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injericsson · enterprise content management · CWE-74 | Высокая8,0 | — | 1,1 % | 17 сент. 2021 г. |
32Наблюдать | CVE-2024-53829Эксплойта нет | Cross-Site Request Forgery in CodeChecker APIericsson · codechecker · CWE-352 | Высокая8,2 | — | 0,3 % | 21 янв. 2025 г. |
31Наблюдать | CVE-2003-1442Proof of concept | The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain ericsson · hm220dp adsl modem · CWE-287 | Высокая7,5 | — | 2,6 % | 31 дек. 2003 г. |
31Наблюдать | CVE-2025-40843Эксплойта нет | Buffer overflow in CodeChecker log commandericsson · codechecker · CWE-121 | Высокая7,8 | — | 0,2 % | 28 окт. 2025 г. |
28Наблюдать | CVE-2015-2166Proof of concept | Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remotericsson · drutt mobile service delivery platform · CWE-22 | Средняя5,0 | — | 26,8 % | 6 апр. 2015 г. |
28Наблюдать | CVE-2024-25007Эксплойта нет | Ericsson Network Manager - Improper Neutralization of Formula Elements Vulnerabilityericsson · network manager · CWE-1236 | Высокая7,1 | — | 0,4 % | 4 апр. 2024 г. |
28Наблюдать | CVE-2026-25658Эксплойта нет | Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerabilityericsson · packet core gateway · CWE-230 | Высокая7,1 | — | 0,3 % | 5 июн. 2026 г. |
28Наблюдать | CVE-2026-25659Эксплойта нет | Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerabilityericsson · packet core gateway · CWE-230 | Высокая7,1 | — | 0,3 % | 5 июн. 2026 г. |
28Наблюдать | CVE-2026-25657Эксплойта нет | Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerabilityericsson · packet core gateway · CWE-228 | Высокая7,1 | — | 0,3 % | 5 июн. 2026 г. |
28Наблюдать | CVE-2025-27260Эксплойта нет | Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerabilityericsson · indoor connect 8855 firmware · CWE-790 | Высокая7,2 | — | 0,2 % | 25 мар. 2026 г. |
28Наблюдать | CVE-2025-59174Эксплойта нет | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially cericsson · packet core controller · CWE-228 | Высокая7,1 | — | 0,2 % | 5 июн. 2026 г. |
27Наблюдать | CVE-2022-46408Эксплойта нет | Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) whereericsson · network manager · CWE-1236 | Средняя6,8 | — | 0,9 % | 28 июн. 2023 г. |
27Наблюдать | CVE-2025-27258Эксплойта нет | Ericsson Network Manager: escalation of privilege vulnerabilityericsson · network manager · CWE-284 | Средняя6,9 | — | 0,3 % | 13 окт. 2025 г. |
27Наблюдать | CVE-2024-25008Эксплойта нет | Ericsson RAN Compute and Site Controller 6610 - Improper Input Validation Vulnerabilityericsson · ericsson ran compute basebands (all bb variants) · CWE-20 | Средняя6,8 | — | 0,3 % | 16 авг. 2024 г. |
- CVE-2024-1008152В плане
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
КритическаяCVSS 10,0Proof of conceptEPSS 40 %ericsson · codechecker6 нояб. 2024 г.
- CVE-2021-4333938Наблюдать
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export
ВысокаяCVSS 8,8Proof of conceptEPSS 10 %ericsson · network location3 нояб. 2021 г.
- CVE-2026-2566037Наблюдать
Authentication bypass for certain API calls
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %ericsson · codechecker24 апр. 2026 г.
- CVE-2024-1008236Наблюдать
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %ericsson · codechecker6 нояб. 2024 г.
- CVE-2022-4753135Наблюдать
An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ericsson · evolved packet gateway5 дек. 2023 г.
- CVE-2023-3990935Наблюдать
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ericsson · network manager7 дек. 2023 г.
- CVE-2025-2726234Наблюдать
Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command Vulnerability
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %ericsson · indoor connect 8855 firmware25 сент. 2025 г.
- CVE-2025-4083634Наблюдать
Ericsson Indoor Connect 8855 - Improper Input Validation Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %ericsson · indoor connect 8855 firmware25 сент. 2025 г.
- CVE-2025-2726134Наблюдать
Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an SQL Command Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %ericsson · indoor connect 8855 firmware25 сент. 2025 г.
- CVE-2025-4083734Наблюдать
Ericsson Indoor Connect 8855 - Missing Authorization Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %ericsson · indoor connect 8855 firmware25 сент. 2025 г.
- CVE-2025-4084234Наблюдать
Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerability
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %ericsson · indoor connect 8855 firmware25 мар. 2026 г.
- CVE-2021-4139032Наблюдать
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Inj
ВысокаяCVSS 8,0Эксплойта нетEPSS 1 %ericsson · enterprise content management17 сент. 2021 г.
- CVE-2024-5382932Наблюдать
Cross-Site Request Forgery in CodeChecker API
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %ericsson · codechecker21 янв. 2025 г.
- CVE-2003-144231Наблюдать
The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %ericsson · hm220dp adsl modem31 дек. 2003 г.
- CVE-2025-4084331Наблюдать
Buffer overflow in CodeChecker log command
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ericsson · codechecker28 окт. 2025 г.
- CVE-2015-216628Наблюдать
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remot
СредняяCVSS 5,0Proof of conceptEPSS 27 %ericsson · drutt mobile service delivery platform6 апр. 2015 г.
- CVE-2024-2500728Наблюдать
Ericsson Network Manager - Improper Neutralization of Formula Elements Vulnerability
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %ericsson · network manager4 апр. 2024 г.
- CVE-2026-2565828Наблюдать
Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %ericsson · packet core gateway5 июн. 2026 г.
- CVE-2026-2565928Наблюдать
Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %ericsson · packet core gateway5 июн. 2026 г.
- CVE-2026-2565728Наблюдать
Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %ericsson · packet core gateway5 июн. 2026 г.
- CVE-2025-2726028Наблюдать
Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerability
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %ericsson · indoor connect 8855 firmware25 мар. 2026 г.
- CVE-2025-5917428Наблюдать
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially c
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %ericsson · packet core controller5 июн. 2026 г.
- CVE-2022-4640827Наблюдать
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where
СредняяCVSS 6,8Эксплойта нетEPSS 1 %ericsson · network manager28 июн. 2023 г.
- CVE-2025-2725827Наблюдать
Ericsson Network Manager: escalation of privilege vulnerability
СредняяCVSS 6,9Эксплойта нетEPSS 0 %ericsson · network manager13 окт. 2025 г.
- CVE-2024-2500827Наблюдать
Ericsson RAN Compute and Site Controller 6610 - Improper Input Validation Vulnerability
СредняяCVSS 6,8Эксплойта нетEPSS 0 %ericsson · ericsson ran compute basebands (all bb variants)16 авг. 2024 г.