CVE-2021-35486

High
|8.1
No Exploit

Plain English Summary

AI-powered analysis for quick understanding

An attacker can exploit this vulnerability to remotely import and overwrite the entire configuration of the Nokia IMPACT application, potentially taking full control of it. This can happen because the application fails to check for a security token that normally helps prevent unauthorized actions, allowing the attacker to execute this without needing to be authenticated.

Technical Description

A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor the CSRF-NONCE cookie is validated.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactNone
ScopeUnchanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$3,316($1K-$5K)
Vendor Response
Grade APatched in 0 days

Quick Information

Published

Mar 3, 2026

about 1 month ago

Last Modified

Mar 4, 2026

about 1 month ago