By vendor
Nokia vulnerabilities
Known CVEs affecting Nokia products, prioritized by severity, with SEC.co remediation and detection guidance.
3 published vulnerabilities
- CVE-2025-24815HIGH 7.8
Nokia MantaRay NM contains a file upload vulnerability that fails to properly validate uploaded file types. An authenticated user with local access could upload malicious files to the system, potentially leading to unauthorized code execution or system compromise. The vulnerability requires valid credentials but poses significant risk once an attacker is inside the network perimeter.
- CVE-2025-7406HIGH 7.8
CVE-2025-7406 is a privilege escalation flaw in Nokia MantaRay NM that allows a local administrator to gain full root access to the system. An attacker who already has administrative privileges on the host can exploit a misconfigured sudo policy to execute arbitrary commands with root-level permissions, bypassing normal access controls. This is a local-only attack requiring existing administrative credentials, but it completely breaks the privilege boundary once successful.
- CVE-2025-24816MEDIUM 6.5
Nokia MantaRay contains a flaw in its API authorization logic that allows an authenticated user to access information they should not be able to see. An attacker with valid credentials could exploit insufficient permission checks to retrieve confidential data beyond their intended access scope. This is a moderate-severity issue requiring attention but does not enable data modification or system disruption.