PT-2022-23308 · Airspan · Airspan Airvelocity 1500

CVE-2022-36312

·

Published

2022-08-16

·

Updated

2022-08-17

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Airspan AirVelocity 1500 version 15.18.00.2511
Description The issue is related to a lack of CSRF protections in the eNodeB's web management UI. This may potentially affect other AirVelocity and AirSpeed models.
Recommendations For Airspan AirVelocity 1500 version 15.18.00.2511, consider disabling access to the web management UI until a patch is available to add CSRF protections. Restrict access to the eNodeB's web management UI to minimize the risk of exploitation.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-36312

Affected Products

Airspan Airvelocity 1500