Ericsson kayıtları
ericsson üreticisine ait 45 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %51,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')9
- CWE-228 Improper Handling of Syntactically Invalid Structure3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')2
- CWE-230 Improper Handling of Missing Values2
- CWE-20 Improper Input Validation2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
45 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2024-10081Kavram kanıtı | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.ericsson · codechecker · CWE-288 | Kritik10,0 | — | %39,9 | 6 Kas 2024 |
38İzleyin | CVE-2021-43339Kavram kanıtı | In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export ericsson · network location · CWE-77 | Yüksek8,8 | — | %9,6 | 3 Kas 2021 |
37İzleyin | CVE-2026-25660İstismar yok | Authentication bypass for certain API callsericsson · codechecker · CWE-290 | Kritik9,3 | — | %0,6 | 24 Nis 2026 |
36İzleyin | CVE-2024-10082İstismar yok | CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.ericsson · codechecker · CWE-305 | Kritik9,0 | — | %0,5 | 6 Kas 2024 |
35İzleyin | CVE-2022-47531İstismar yok | An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users toericsson · evolved packet gateway | Yüksek8,8 | — | %1,0 | 5 Ara 2023 |
35İzleyin | CVE-2023-39909İstismar yok | Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.ericsson · network manager | Yüksek8,8 | — | %0,8 | 7 Ara 2023 |
34İzleyin | CVE-2025-27262İstismar yok | Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command Vulnerabilityericsson · indoor connect 8855 firmware · CWE-78 | Yüksek8,5 | — | %0,7 | 25 Eyl 2025 |
34İzleyin | CVE-2025-40836İstismar yok | Ericsson Indoor Connect 8855 - Improper Input Validation Vulnerabilityericsson · indoor connect 8855 firmware · CWE-20 | Yüksek8,7 | — | %0,4 | 25 Eyl 2025 |
34İzleyin | CVE-2025-27261İstismar yok | Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an SQL Command Vulnerabilityericsson · indoor connect 8855 firmware · CWE-89 | Yüksek8,7 | — | %0,3 | 25 Eyl 2025 |
34İzleyin | CVE-2025-40837İstismar yok | Ericsson Indoor Connect 8855 - Missing Authorization Vulnerabilityericsson · indoor connect 8855 firmware · CWE-862 | Yüksek8,7 | — | %0,3 | 25 Eyl 2025 |
34İzleyin | CVE-2025-40842İstismar yok | Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerabilityericsson · indoor connect 8855 firmware · CWE-79 | Yüksek8,5 | — | %0,1 | 25 Mar 2026 |
32İzleyin | CVE-2021-41390İstismar yok | In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Injericsson · enterprise content management · CWE-74 | Yüksek8,0 | — | %1,1 | 17 Eyl 2021 |
32İzleyin | CVE-2024-53829İstismar yok | Cross-Site Request Forgery in CodeChecker APIericsson · codechecker · CWE-352 | Yüksek8,2 | — | %0,3 | 21 Oca 2025 |
31İzleyin | CVE-2003-1442Kavram kanıtı | The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain ericsson · hm220dp adsl modem · CWE-287 | Yüksek7,5 | — | %2,6 | 31 Ara 2003 |
31İzleyin | CVE-2025-40843İstismar yok | Buffer overflow in CodeChecker log commandericsson · codechecker · CWE-121 | Yüksek7,8 | — | %0,2 | 28 Eki 2025 |
28İzleyin | CVE-2015-2166Kavram kanıtı | Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remotericsson · drutt mobile service delivery platform · CWE-22 | Orta5,0 | — | %26,8 | 6 Nis 2015 |
28İzleyin | CVE-2024-25007İstismar yok | Ericsson Network Manager - Improper Neutralization of Formula Elements Vulnerabilityericsson · network manager · CWE-1236 | Yüksek7,1 | — | %0,4 | 4 Nis 2024 |
28İzleyin | CVE-2026-25658İstismar yok | Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerabilityericsson · packet core gateway · CWE-230 | Yüksek7,1 | — | %0,3 | 5 Haz 2026 |
28İzleyin | CVE-2026-25659İstismar yok | Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerabilityericsson · packet core gateway · CWE-230 | Yüksek7,1 | — | %0,3 | 5 Haz 2026 |
28İzleyin | CVE-2026-25657İstismar yok | Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerabilityericsson · packet core gateway · CWE-228 | Yüksek7,1 | — | %0,3 | 5 Haz 2026 |
28İzleyin | CVE-2025-27260İstismar yok | Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerabilityericsson · indoor connect 8855 firmware · CWE-790 | Yüksek7,2 | — | %0,2 | 25 Mar 2026 |
28İzleyin | CVE-2025-59174İstismar yok | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially cericsson · packet core controller · CWE-228 | Yüksek7,1 | — | %0,2 | 5 Haz 2026 |
27İzleyin | CVE-2022-46408İstismar yok | Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) whereericsson · network manager · CWE-1236 | Orta6,8 | — | %0,9 | 28 Haz 2023 |
27İzleyin | CVE-2025-27258İstismar yok | Ericsson Network Manager: escalation of privilege vulnerabilityericsson · network manager · CWE-284 | Orta6,9 | — | %0,3 | 13 Eki 2025 |
27İzleyin | CVE-2024-25008İstismar yok | Ericsson RAN Compute and Site Controller 6610 - Improper Input Validation Vulnerabilityericsson · ericsson ran compute basebands (all bb variants) · CWE-20 | Orta6,8 | — | %0,3 | 16 Ağu 2024 |
- CVE-2024-1008152Planlayın
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
KritikCVSS 10,0Kavram kanıtıEPSS %40ericsson · codechecker6 Kas 2024
- CVE-2021-4333938İzleyin
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export
YüksekCVSS 8,8Kavram kanıtıEPSS %10ericsson · network location3 Kas 2021
- CVE-2026-2566037İzleyin
Authentication bypass for certain API calls
KritikCVSS 9,3İstismar yokEPSS %1ericsson · codechecker24 Nis 2026
- CVE-2024-1008236İzleyin
CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy.
KritikCVSS 9,0İstismar yokEPSS %0ericsson · codechecker6 Kas 2024
- CVE-2022-4753135İzleyin
An issue was discovered in Ericsson Evolved Packet Gateway (EPG) versions 3.x before 3.25 and 2.x before 2.16, allows authenticated users to
YüksekCVSS 8,8İstismar yokEPSS %1ericsson · evolved packet gateway5 Ara 2023
- CVE-2023-3990935İzleyin
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.
YüksekCVSS 8,8İstismar yokEPSS %1ericsson · network manager7 Ara 2023
- CVE-2025-2726234İzleyin
Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an OS Command Vulnerability
YüksekCVSS 8,5İstismar yokEPSS %1ericsson · indoor connect 8855 firmware25 Eyl 2025
- CVE-2025-4083634İzleyin
Ericsson Indoor Connect 8855 - Improper Input Validation Vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0ericsson · indoor connect 8855 firmware25 Eyl 2025
- CVE-2025-2726134İzleyin
Ericsson Indoor Connect 8855 - Improper Neutralization of Special Elements used in an SQL Command Vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0ericsson · indoor connect 8855 firmware25 Eyl 2025
- CVE-2025-4083734İzleyin
Ericsson Indoor Connect 8855 - Missing Authorization Vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0ericsson · indoor connect 8855 firmware25 Eyl 2025
- CVE-2025-4084234İzleyin
Ericsson Indoor Connect 8855 - Improper Neutralization of Input During Web Page Generation Vulnerability
YüksekCVSS 8,5İstismar yokEPSS %0ericsson · indoor connect 8855 firmware25 Mar 2026
- CVE-2021-4139032İzleyin
In Ericsson ECM before 18.0, it was observed that Security Provider Endpoint in the User Profile Management Section is vulnerable to CSV Inj
YüksekCVSS 8,0İstismar yokEPSS %1ericsson · enterprise content management17 Eyl 2021
- CVE-2024-5382932İzleyin
Cross-Site Request Forgery in CodeChecker API
YüksekCVSS 8,2İstismar yokEPSS %0ericsson · codechecker21 Oca 2025
- CVE-2003-144231İzleyin
The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remote attackers to gain
YüksekCVSS 7,5Kavram kanıtıEPSS %3ericsson · hm220dp adsl modem31 Ara 2003
- CVE-2025-4084331İzleyin
Buffer overflow in CodeChecker log command
YüksekCVSS 7,8İstismar yokEPSS %0ericsson · codechecker28 Eki 2025
- CVE-2015-216628İzleyin
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remot
OrtaCVSS 5,0Kavram kanıtıEPSS %27ericsson · drutt mobile service delivery platform6 Nis 2015
- CVE-2024-2500728İzleyin
Ericsson Network Manager - Improper Neutralization of Formula Elements Vulnerability
YüksekCVSS 7,1İstismar yokEPSS %0ericsson · network manager4 Nis 2024
- CVE-2026-2565828İzleyin
Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
YüksekCVSS 7,1İstismar yokEPSS %0ericsson · packet core gateway5 Haz 2026
- CVE-2026-2565928İzleyin
Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
YüksekCVSS 7,1İstismar yokEPSS %0ericsson · packet core gateway5 Haz 2026
- CVE-2026-2565728İzleyin
Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
YüksekCVSS 7,1İstismar yokEPSS %0ericsson · packet core gateway5 Haz 2026
- CVE-2025-2726028İzleyin
Ericsson Indoor Connect 8855 - Improper Filtering of Special Elements Vulnerability
YüksekCVSS 7,2İstismar yokEPSS %0ericsson · indoor connect 8855 firmware25 Mar 2026
- CVE-2025-5917428İzleyin
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially c
YüksekCVSS 7,1İstismar yokEPSS %0ericsson · packet core controller5 Haz 2026
- CVE-2022-4640827İzleyin
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where
OrtaCVSS 6,8İstismar yokEPSS %1ericsson · network manager28 Haz 2023
- CVE-2025-2725827İzleyin
Ericsson Network Manager: escalation of privilege vulnerability
OrtaCVSS 6,9İstismar yokEPSS %0ericsson · network manager13 Eki 2025
- CVE-2024-2500827İzleyin
Ericsson RAN Compute and Site Controller 6610 - Improper Input Validation Vulnerability
OrtaCVSS 6,8İstismar yokEPSS %0ericsson · ericsson ran compute basebands (all bb variants)16 Ağu 2024