Записи Nokia
153 опубликованных записей вендора nokia.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 17
- С записью об исправлении
- 9,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')10
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')10
- CWE-20 Improper Input Validation8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-312 Cleartext Storage of Sensitive Information5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
153 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2021-31932Эксплойта нет | Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass.nokia · bts trs web console | Критическая9,8 | — | 21,6 % | 11 февр. 2022 г. |
44В плане | CVE-2005-2277Proof of concept | Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters inokia · affix | Критическая10,0 | — | 12,9 % | 15 июл. 2005 г. |
42В плане | CVE-2008-3553Эксплойта нет | Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vecnokia · series 40 · CWE-264 | Критическая10,0 | — | 5,9 % | 8 авг. 2008 г. |
42В плане | CVE-2008-3552Эксплойта нет | Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbitnokia · series 40 | Критическая10,0 | — | 5,9 % | 8 авг. 2008 г. |
41В плане | CVE-2019-3922Эксплойта нет | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST renokia · i-240w-q gpon ont firmware · CWE-121 | Критическая9,8 | — | 5,2 % | 5 мар. 2019 г. |
40В плане | CVE-2019-3921Proof of concept | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST renokia · i-240w-q gpon ont firmware · CWE-121 | Высокая8,8 | — | 17,9 % | 5 мар. 2019 г. |
40В плане | CVE-2022-39815Эксплойта нет | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.nokia · 1350 optical management system · CWE-78 | Критическая9,8 | — | 2,1 % | 13 сент. 2022 г. |
40В плане | CVE-2019-3918Эксплойта нет | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH inokia · i-240w-q gpon ont firmware · CWE-798 | Критическая9,8 | — | 2,0 % | 5 мар. 2019 г. |
40В плане | CVE-2021-41487Эксплойта нет | NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.nokia · vitalsuite · CWE-89 | Критическая9,8 | — | 1,8 % | 16 июн. 2022 г. |
39Наблюдать | CVE-2011-0498Proof of concept | Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to cnokia · multimedia player · CWE-119 | Критическая9,3 | — | 5,7 % | 20 янв. 2011 г. |
39Наблюдать | CVE-2009-0734Proof of concept | Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code vnokia · nokia pc suite · CWE-119 | Критическая9,3 | — | 5,1 % | 25 февр. 2009 г. |
39Наблюдать | CVE-2023-41351Эксплойта нет | Chunghwa Telecom NOKIA G-040W-Q - Broken Access Controlnokia · g-040w-q firmware · CWE-288 | Критическая9,8 | — | 0,8 % | 3 нояб. 2023 г. |
39Наблюдать | CVE-2023-41350Эксплойта нет | Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attemptsnokia · g-040w-q firmware · CWE-307 | Критическая9,8 | — | 0,8 % | 3 нояб. 2023 г. |
39Наблюдать | CVE-2023-41355Эксплойта нет | Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validationnokia · g-040w-q firmware · CWE-940 | Критическая9,8 | — | 0,6 % | 3 нояб. 2023 г. |
39Наблюдать | CVE-2025-27020Эксплойта нет | Improper configuration of SSH service in Infinera MTC-9nokia · infinera mtc-9 firmware · CWE-306 | Критическая9,8 | — | 0,5 % | 8 дек. 2025 г. |
39Наблюдать | CVE-2025-27019Эксплойта нет | Remote shell service (RSH) in Infinera MTC-9nokia · infinera mtc-9 firmware · CWE-306 | Критическая9,8 | — | 0,4 % | 8 дек. 2025 г. |
36Наблюдать | CVE-2019-3920Эксплойта нет | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTPnokia · i-240w-q gpon ont firmware · CWE-78 | Высокая8,8 | — | 3,9 % | 5 мар. 2019 г. |
36Наблюдать | CVE-2019-3919Эксплойта нет | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent nokia · i-240w-q gpon ont firmware · CWE-78 | Высокая8,8 | — | 3,9 % | 5 мар. 2019 г. |
36Наблюдать | CVE-2019-17403Эксплойта нет | Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.nokia · impact · CWE-434 | Высокая8,8 | — | 2,5 % | 25 нояб. 2019 г. |
36Наблюдать | CVE-2022-39818Эксплойта нет | In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET parnokia · network functions manager for transport · CWE-78 | Высокая8,8 | — | 2,2 % | 25 дек. 2023 г. |
36Наблюдать | CVE-2024-25660Эксплойта нет | The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthonokia · transcend network management system · CWE-266 | Критическая9,0 | — | 0,6 % | 1 окт. 2024 г. |
36Наблюдать | CVE-2025-24936Эксплойта нет | Insufficient Validation of Input in the URLnokia · wavesuite noc · CWE-78 | Критическая9,0 | — | 0,4 % | 21 июл. 2025 г. |
36Наблюдать | CVE-2025-24937Эксплойта нет | Access to local file system and its contentnokia · wavesuite noc · CWE-98 | Критическая9,0 | — | 0,2 % | 21 июл. 2025 г. |
35Наблюдать | CVE-2021-45896Эксплойта нет | Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use ofnokia · fastmile firmware | Высокая8,8 | — | 1,6 % | 27 дек. 2021 г. |
35Наблюдать | CVE-2022-39819Эксплойта нет | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.nokia · 1350 optical management system · CWE-78 | Высокая8,8 | — | 1,5 % | 13 сент. 2022 г. |
- CVE-2021-3193245В плане
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass.
КритическаяCVSS 9,8Эксплойта нетEPSS 22 %nokia · bts trs web console11 февр. 2022 г.
- CVE-2005-227744В плане
Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters i
КритическаяCVSS 10,0Proof of conceptEPSS 13 %nokia · affix15 июл. 2005 г.
- CVE-2008-355342В плане
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vec
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %nokia · series 408 авг. 2008 г.
- CVE-2008-355242В плане
Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition FP1, and possibly later devices, allow remote attackers to execute arbit
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %nokia · series 408 авг. 2008 г.
- CVE-2019-392241В плане
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST re
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %nokia · i-240w-q gpon ont firmware5 мар. 2019 г.
- CVE-2019-392140В плане
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST re
ВысокаяCVSS 8,8Proof of conceptEPSS 18 %nokia · i-240w-q gpon ont firmware5 мар. 2019 г.
- CVE-2022-3981540В плане
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nokia · 1350 optical management system13 сент. 2022 г.
- CVE-2019-391840В плане
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH i
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nokia · i-240w-q gpon ont firmware5 мар. 2019 г.
- CVE-2021-4148740В плане
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nokia · vitalsuite16 июн. 2022 г.
- CVE-2011-049839Наблюдать
Stack-based buffer overflow in Nokia Multimedia Player 1.00.55.5010, and possibly other versions, allows user-assisted remote attackers to c
КритическаяCVSS 9,3Proof of conceptEPSS 6 %nokia · multimedia player20 янв. 2011 г.
- CVE-2009-073439Наблюдать
Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code v
КритическаяCVSS 9,3Proof of conceptEPSS 5 %nokia · nokia pc suite25 февр. 2009 г.
- CVE-2023-4135139Наблюдать
Chunghwa Telecom NOKIA G-040W-Q - Broken Access Control
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nokia · g-040w-q firmware3 нояб. 2023 г.
- CVE-2023-4135039Наблюдать
Chunghwa Telecom NOKIA G-040W-Q - Excessive Authentication Attempts
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nokia · g-040w-q firmware3 нояб. 2023 г.
- CVE-2023-4135539Наблюдать
Chunghwa Telecom NOKIA G-040W-Q - Improper Input Validation
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nokia · g-040w-q firmware3 нояб. 2023 г.
- CVE-2025-2702039Наблюдать
Improper configuration of SSH service in Infinera MTC-9
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nokia · infinera mtc-9 firmware8 дек. 2025 г.
- CVE-2025-2701939Наблюдать
Remote shell service (RSH) in Infinera MTC-9
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %nokia · infinera mtc-9 firmware8 дек. 2025 г.
- CVE-2019-392036Наблюдать
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %nokia · i-240w-q gpon ont firmware5 мар. 2019 г.
- CVE-2019-391936Наблюдать
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %nokia · i-240w-q gpon ont firmware5 мар. 2019 г.
- CVE-2019-1740336Наблюдать
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %nokia · impact25 нояб. 2019 г.
- CVE-2022-3981836Наблюдать
In NOKIA NFM-T R19.9, an OS Command Injection vulnerability occurs in /cgi-bin/R19.9/log.pl of the VM Manager WebUI via the cmd HTTP GET par
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %nokia · network functions manager for transport25 дек. 2023 г.
- CVE-2024-2566036Наблюдать
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unautho
КритическаяCVSS 9,0Эксплойта нетEPSS 1 %nokia · transcend network management system1 окт. 2024 г.
- CVE-2025-2493636Наблюдать
Insufficient Validation of Input in the URL
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %nokia · wavesuite noc21 июл. 2025 г.
- CVE-2025-2493736Наблюдать
Access to local file system and its content
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %nokia · wavesuite noc21 июл. 2025 г.
- CVE-2021-4589635Наблюдать
Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %nokia · fastmile firmware27 дек. 2021 г.
- CVE-2022-3981935Наблюдать
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %nokia · 1350 optical management system13 сент. 2022 г.