CVE-2022-40713

CVE-2022-40713 – Nokia 1350 OMS Optical Management System

Vulnerability Description: Multiple Relative Path Traversal - CWE-23

Software Version: R14.2

NIST: https://nvd.nist.gov/vuln/detail/CVE-2022-40713

CVSv3: 6.5

Severity: Medium

Credits: Luca Carbone, Fabio Romano, Stefano Scipioni, Massimiliano Brolli

An issue was discovered in NOKIA 1350OMS R14.2. Multiple Relative Path Traversal issues exist in different specific endpoints via the file parameter, allowing a remote authenticated attacker to read files on the filesystem arbitrarily.