CVE-2021-35485

High
|8.0
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker with valid login credentials to upload malicious executable files to the server, which could lead to unauthorized control over the system. It can be exploited when adding or editing applications within the Nokia IMPACT platform.

Technical Description

The Applications component of Nokia IMPACT version through 19.11.2.10-20210118042150283 allows an authenticated user to arbitrarily upload server-side executable files via the /ui/rest-proxy/application fileupload parameter. This can occur during the adding of a new application, or during the editing of an existing one.

CVSS Vector Analysis

Attack VectorAdjacent Network
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References