VendorsEricssonnetwork_managerall versions
Vulnerabilities

Ericsson Network Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-27258
Ericsson Network Manager: escalation of privilege vulnerability
Published 2025-10-13 · Analyzed
9.8EPSS 0.003
CVE-2023-39909
Ericsson Network Manager before 23.2 mishandles Access Control and thus unauthenticated low-privilege users can access the NCM application.
Published 2023-12-07 · Modified
8.8EPSS 0.008
CVE-2024-25007
Ericsson Network Manager - Improper Neutralization of Formula Elements Vulnerability
Published 2024-04-04 · Modified
7.1EPSS 0.004
CVE-2022-46408
Ericsson Network Manager (ENM), versions prior to 22.1, contains a vulnerability in the application Network Connectivity Manager (NCM) where improper Neutralization of Formula Elements in a CSV File can lead to remote code execution or data leakage via maliciously injected hyperlinks. The attacker would need admin/elevated access to exploit the vulnerability.
Published 2023-06-29 · Modified
6.8EPSS 0.009
CVE-2021-28488
Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).
Published 2022-03-08 · Modified
6.5EPSS 0.011
CVE-2025-27259
Ericsson Network Manager: improper neutralization of user controlled input
Published 2025-10-13 · Analyzed
5.4EPSS 0.002
CVE-2021-32570
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all must be previously defined and authorized by the Security Administrator. Those users can access some log’s files, under a common path, and read information stored in the log’s files in order to conduct privilege escalation.
Published 2022-08-25 · Modified
4.9EPSS 0.008
CVE-2022-46407
Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of ENM deployment. The attacker would need admin/elevated access to exploit the vulnerability
Published 2023-06-29 · Modified
4.8EPSS 0.003