CVE-2022-21176
Published on: Not Yet Published
Last Modified on: 02/28/2022 05:49:47 PM UTC
Certain versions of A5x from Airspan contain the following vulnerability:
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input, which may allow an attacker to perform a SQL injection and obtain sensitive information.
- CVE-2022-21176 has been assigned by
ics-[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Airspan Networks - MMP version < v1.0.3
- Affected Vendor/Software:
Airspan Networks - PTP C-series version < v2.8.6.1
- Affected Vendor/Software:
Airspan Networks - PTMP C-series and A5x version < v2.5.4.1
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Airspan Networks Mimosa | CISA | Third Party Advisory US Government Resource www.cisa.gov text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Airspan | A5x | - | All | All | All |
Operating System | Airspan | A5x Firmware | All | All | All | All |
Hardware
| Airspan | C5c | - | All | All | All |
Operating System | Airspan | C5c Firmware | All | All | All | All |
Hardware
| Airspan | C5x | - | All | All | All |
Operating System | Airspan | C5x Firmware | All | All | All | All |
Hardware
| Airspan | C6x | - | All | All | All |
Operating System | Airspan | C6x Firmware | All | All | All | All |
Application | Airspan | Mimosa Management Platform | All | All | All | All |
- cpe:2.3:h:airspan:a5x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:airspan:a5x_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:airspan:c5c:-:*:*:*:*:*:*:*:
- cpe:2.3:o:airspan:c5c_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:airspan:c5x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:airspan:c5x_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:airspan:c6x:-:*:*:*:*:*:*:*:
- cpe:2.3:o:airspan:c6x_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:a:airspan:mimosa_management_platform:*:*:*:*:*:*:*:*:
Discovery Credit
Noam Moshe of Claroty reported these vulnerabilities to CISA.
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Airspan Networks Mimosa product line SQL injection | CVE-2022-21176 - redpacketsecurity.com/airspan-networ… | 2022-02-07 11:01:55 |