Nokia IMPACT
cpe:2.3:a:nokia:impact:*:*:*:*:*:*:*
- <= 19.11.2.10-20210118042150283
A Cross-Site Request Forgery (CSRF) vulnerability exists in Nokia IMPACT versions through 19.11.2.10-20210118042150283. This vulnerability allows remote attackers to import and overwrite the entire application configuration. The issue arises in the '/ui/rest-proxy/entity/import' endpoint, where the X-CSRF-NONCE HTTP header and the CSRF-NONCE cookie are not properly validated.
Exploitation of this vulnerability could lead to unauthorized modification of the application configuration, potentially allowing attackers to disrupt services or manipulate application behavior.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.