A new bug was recently discovered in Ericsson Network Manager product by the TIM Red Team Research.
The bug focuses on the CWE Exposure of Resource to Wrong Sphere and results in incorrect access-control behavior.
Variuos security issues can be encountered of it gets exploited.
Source: https://securityaffairs.co/wordpress/129188/hacking/ericsson-network-manager-bug.html
TPRM report: https://scoringcyber.rankiteo.com/company/ericsson
"id": "eri1721322",
"linkid": "ericsson",
"type": "Vulnerability",
"date": "03/2022",
"severity": "80",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Telecommunications',
'name': 'Ericsson',
'type': 'Corporation'}],
'attack_vector': 'Exposure of Resource to Wrong Sphere',
'description': 'A new bug was recently discovered in Ericsson Network Manager '
'product by the TIM Red Team Research. The bug focuses on the '
'CWE Exposure of Resource to Wrong Sphere and results in '
'incorrect access-control behavior. Various security issues '
'can be encountered if it gets exploited.',
'threat_actor': 'TIM Red Team Research',
'title': 'Ericsson Network Manager Product Bug',
'type': 'Vulnerability',
'vulnerability_exploited': 'CWE Exposure of Resource to Wrong Sphere'}