CVE-2021-28485
Last modified
CVE-2021-28485 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ericsson | Mobile Switching Center Server Bc 18a Firmware | >= is_3.1, < is_3.1_cp22 |
References
- https://www.ericsson.com/en/about-us/security/psirtVendor Advisory
- https://www.gruppotim.it/it/footer/red-team.htmlThird Party Advisory
- https://www.ericsson.com/en/about-us/security/psirtVendor Advisory
- https://www.gruppotim.it/it/footer/red-team.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-28485?
How severe is CVE-2021-28485?
How do I fix CVE-2021-28485?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-28479Windows CSC Service Information Disclosure Vulnerability5.5
- CVE-2021-28480Microsoft Exchange Server Remote Code Execution Vulnerabilit…9.8
- CVE-2021-28481Microsoft Exchange Server Remote Code Execution Vulnerabilit…9.8
- CVE-2021-28482Microsoft Exchange Server Remote Code Execution Vulnerabilit…8.8
- CVE-2021-28483Microsoft Exchange Server Remote Code Execution Vulnerabilit…9
- CVE-2021-28484An issue was discovered in the /api/connector endpoint handl…7.5
- CVE-2021-28488Ericsson Network Manager (ENM) before 21.2 has incorrect acc…6.5
- CVE-2021-28490In OWASP CSRFGuard through 3.1.0, CSRF can occur because the…8.8
- CVE-2021-28492Unisys Stealth (core) 5.x before 5.0.048.0, 5.1.x before 5.1…4.9
- CVE-2021-28493In Arista's MOS (Metamako Operating System) software which i…7.8
- CVE-2021-28494In Arista's MOS (Metamako Operating System) software which i…8.8
- CVE-2021-28495In Arista's MOS (Metamako Operating System) software which i…9.8
Are you affected by CVE-2021-28485?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
