Vulnerability Details CVE-2021-28485
In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 57.6%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2021-28485
-
cpe:2.3:h:ericsson:mobile_switching_center_server_bc_18a:-
-
cpe:2.3:o:ericsson:mobile_switching_center_server_bc_18a_firmware:is_3.1