Nokia
First CVE: Oct 17, 2024Active for: 2 years
26
CVEs Published
More CVEs Published than 46% of tracked CNAs
8.7
Avg CVEs / Year
More Avg CVEs / Year than 49% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Nokia as a CNA, 38.5% affect products that Nokia develops as a vendor.
38.5%
61.5%
Self-reported: 10Third-party: 16
Of all the CVEs published that affect products developed by Nokia, 6.7% are self-published by Nokia as a CNA.
93.3%
Self-published: 10Published by other CNAs: 140
Trends Over Time
The number and severity of CVEs published by Nokia over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 17, 2024
21 months ago
Most Recent CVE
Jun 30, 2026
24 days ago
Top CVEs
All CVEs published by Nokia as a CNA, regardless of affected vendor or product.
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-7406HIGH Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root pri | Jun 30, 2026 | 7.8 | 33 | NO | NO |
CVE-2025-24815HIGH Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to | Jun 30, 2026 | 7.8 | 32 | NO | NO |
CVE-2025-24816MEDIUM Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacke | Jun 30, 2026 | 6.5 | 30 | NO | NO |
CVE-2023-49564HIGH The CBIS/NCS Manager API is vulnerable to an authentication bypass. By sending a specially crafted HTTP header, an unauthenticated user can gain unauthorized access to API function | Sep 18, 2025 | 8.8 | 29 | NO | NO |
CVE-2023-49565HIGH The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD | Sep 18, 2025 | 8.4 | 28 | NO | NO |
CVE-2025-24937CRITICAL File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web applicati | Jul 21, 2025 | 9.0 | 28 | NO | NO |
CVE-2025-24936CRITICAL The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the se | Jul 21, 2025 | 9.0 | 28 | NO | NO |
CVE-2025-9974HIGH The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-level command execution. Due to | Feb 2, 2026 | 8.0 | 27 | NO | NO |
CVE-2025-24818HIGH Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application. | Apr 7, 2026 | 8.0 | 26 | NO | NO |
CVE-2025-24817HIGH Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application. | Apr 7, 2026 | 8.0 | 26 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA26 CVEs
12%
42%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (38.5%)
Network1 (3.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network15 (57.7%)
Attack Complexity
Low18 (69.2%)
High8 (30.8%)
Unknown0 (0.0%)
User Interaction
None25 (96.2%)
Unknown0 (0.0%)
Required1 (3.8%)
Privileges Required
Low14 (53.8%)
High11 (42.3%)
None1 (3.8%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (26 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Nokia as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Nokia as a CNA — matched by CVE ID, not by organization name.