CVE Feed

    Dashboard / CVE / CVE-2023-22618

    CVE-2023-22618

    If Security Hardening guide rules are not followed, then Nokia WaveLite products allow a local user to create new users with administrative privileges by manipulating a web request. This affects (for example) WaveLite Metro 200 and Fan, WaveLite Metro 200 OPS and Fans, WaveLite Metro 200 and F2B fans, WaveLite Metro 200 OPS and F2B fans, WaveLite Metro 200 NE and F2B fans, and WaveLite Metro 200 NE OPS and F2B fans.

    Published:Oct 4, 2023
    Last Modified:Nov 21, 2024
    EPS:Oct 4, 2023
    EPSS Score:0.00045
    CVSS Score:8.1

    Affected Products

    Vendor
    Nokia
    Product
    Wavelite Metro 200 And F2b Fans
    Vendor
    Nokia
    Product
    Wavelite Metro 200 And F2b Fans Firmware
    Vendor
    Nokia
    Product
    Wavelite Metro 200 And Fan
    Vendor
    Nokia
    Product
    Wavelite Metro 200 And Fan Firmware
    Vendor
    Nokia
    Product
    Wavelite Metro 200 Ne And F2b Fans
    Vendor
    Nokia
    Product
    Wavelite Metro 200 Ne And F2b Fans Firmware
    Vendor
    Nokia
    Product
    Wavelite Metro 200 Ne Ops And F2b Fans
    Vendor
    Nokia
    Product
    Wavelite Metro 200 Ne Ops And F2b Fans Firmware
    Vendor
    Nokia
    Product
    Wavelite Metro 200 Ops And F2b Fans
    Vendor
    Nokia
    Product
    Wavelite Metro 200 Ops And F2b Fans Firmware
    Vendor
    Nokia
    Product
    Wavelite Metro 200 Ops And Fans
    Vendor
    Nokia
    Product
    Wavelite Metro 200 Ops And Fans Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High