Nokia IMPACT Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in Nokia IMPACT versions through 19.11.2.10-20210118042150283. This vulnerability allows remote attackers to import and overwrite the entire application configuration. The issue arises in the '/ui/rest-proxy/entity/import' endpoint, where the X-CSRF-NONCE HTTP header and the CSRF-NONCE cookie are not properly validated.

Impact

Exploitation of this vulnerability could lead to unauthorized modification of the application configuration, potentially allowing attackers to disrupt services or manipulate application behavior.

Added: Mar 3, 2026, 6:26 PM
Updated: Mar 3, 2026, 10:31 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.2
remediation
0.0
relevance
3.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.