HomeSecurityCISA warns of critical vulnerabilities in Airspan Networks Mimosa

CISA warns of critical vulnerabilities in Airspan Networks Mimosa

CISA has warned of critical vulnerabilities in Airspan Networks Mimosa, some of which have earned CVSS severity scores of 10, the highest possible.

Airspan Networks Mimosa

See also: US: Cyberattacks originating from China are more than all other countries combined

When security vulnerabilities are serious and the products they affect are popular or critical to the operations of key industries, the U.S. Cybersecurity and Infrastructure Security Administration (CISA) issues advisories to ensure that IT administrators and security personnel are informed.

On Thursday, CISA issued such an advisory for Airspan Networks Mimosa. The Mimosa devices are offered to industrial and enterprise players for point-to-multipoint (PTMP) network deployment.

Seven vulnerabilities have been included in the advisory, detailing the bugs that earn CVSS v3 baseline scores ranging from 6.5 to 10.0.

Airspan Networks products affected by the vulnerabilities are the Mimosa Management Platform (MMP) prior to version 1.0.3, C-series PTP devices running firmware prior to version 2.8.6.1, and PTMP C-series and A5x devices running firmware below version 2.5.4.1.

CISA warns of critical vulnerabilities in Airspan Networks Mimosa

See also: Zimbra zero-day vulnerability allows email theft

Noam Moshe, from Claroty, mentioned the security issues, which are said to be exploitable remotely and with low attack complexity.

The vulnerabilities are the following:

  • CVE-2022-21196 (CVSS 10.0): Improper authorization flaw caused by failures to perform authentication checks on many API routes, leading to denial-of-service, information leaks, and remote code execution (RCE).
  • CVE-2022-21141 (CVSS 10.0): Additional failures in performing authorization checks in API functions, leading to the same attack vectors.
  • CVE-2022-21215 (CVSS 10.0): A server side request forgery (SSRF) flaw that can be exploited by an attacker to force a server to grant access to support APIs.
  • CVE-2022-21176 (CVSS 8.6): Improper neutralization of elements in SQL commands. Lack of input sanitization could lead to SQL injections and data leaks.
  • CVE-2022-0138 (CVSS 7.5): A deserialization function does not properly validate or check data input, allowing the creation of arbitrary classes.
  • CVE-2022-21143 (CVSS 9.8): User input is not properly sanitized in certain areas, giving attackers the opportunity to execute arbitrary commands.
  • CVE-2022-21800 (CVSS 6.5): The product line uses the MD5 algorithm for password hashing, but failed to salt the hash, causing a higher risk of sensitive data being vulnerable to hacking attempts.

See also: Intuit warns of phishing emails threatening to delete accounts

There is no indication that the vulnerabilities have been exploited. Airspan Networks recommends that customers upgrade to MMP version 1.0.4 or later, PTP C5x/C5c (v2.90 or later), and PTMP C-series/A5x v.2.9.0 or later.

Information source: zdnet.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS