Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the OSM components, retrieve confidential information, or gain access other parts of a Telco Operator infrastructure other than OSM itself.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Osm
Osm n2vc |
|
| CPEs | cpe:2.3:a:osm:N2VC:7:*:*:*:*:*:*:* | |
| Vendors & Products |
Osm
Osm n2vc |
|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T09:36:44.073Z
Reserved: 2022-07-11T00:00:00.000Z
Link: CVE-2022-35503
Updated: 2024-08-03T09:36:44.073Z
Status : Awaiting Analysis
Published: 2024-04-22T15:15:46.590
Modified: 2024-11-21T07:11:15.403
Link: CVE-2022-35503
No data.
OpenCVE Enrichment
No data.