Improper verification of a user input in Open Source MANO...
High severity
Unreviewed
Published
Apr 22, 2024
to the GitHub Advisory Database
•
Updated Jul 3, 2024
Description
Published by the National Vulnerability Database
Apr 22, 2024
Published to the GitHub Advisory Database
Apr 22, 2024
Last updated
Jul 3, 2024
Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the OSM components, retrieve confidential information, or gain access other parts of a Telco Operator infrastructure other than OSM itself.
References