CVE detail
CVE-2021-28485 — CVE-2021-28485
Published 2023-09-14 · Modified 2026-06-17 · Vendor ericsson · Product mobile_switching_center_server_bc_18a_firmware · Source nvd
MEDIUM
severity
CVSS-derived band
0.0055
EPSS probability
exploitation probability, 30d
43.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References