Ericsson Indoor Connect Command Injection Vulnerability
Vulnerability
A command injection vulnerability has been identified in Ericsson Indoor Connect version 8855. This vulnerability allows for unauthorized execution of commands, which could be done with escalated privileges. Exploitation of this vulnerability may lead to a loss of integrity and confidentiality, unauthorized disclosure and modification of user and configuration data, disruption of service availability, and unauthorized changes to system files and configuration data.
Impact
Exploitation of this vulnerability could result in unauthorized execution of commands with elevated privileges, allowing an attacker to manipulate system files and configuration data, disrupt service availability, and access or modify user and configuration data without authorization.
Remediation
Users are advised to upgrade to Ericsson Indoor Connect version 2025.Q2, which addresses this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
