CVE Feed

    Dashboard / CVE / CVE-2022-35503

    CVE-2022-35503

    Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the OSM components, retrieve confidential information, or gain access other parts of a Telco Operator infrastructure other than OSM itself.

    Published:Apr 22, 2024
    Last Modified:Apr 15, 2026
    EPS:Apr 22, 2024
    EPSS Score:0.00199
    CVSS Score:7.5

    Affected Products

    Vendor
    Osm
    Product
    N2VC

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High