CVE detail
CVE-2021-35486 — CVE-2021-35486
Published 2026-03-03 · Modified 2026-06-17 · Vendor nokia · Product impact_mobile · Source nvd
HIGH
severity
CVSS-derived band
0.0019
EPSS probability
exploitation probability, 30d
8.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor the CSRF-NONCE cookie is validated.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References