Nokia

First CVE: Oct 17, 2024Active for: 2 years
26
CVEs Published
More CVEs Published than 46% of tracked CNAs
8.7
Avg CVEs / Year
More Avg CVEs / Year than 49% of tracked CNAs
6.7
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Nokia as a CNA, 38.5% affect products that Nokia develops as a vendor.

38.5%
61.5%
Self-reported: 10Third-party: 16

Of all the CVEs published that affect products developed by Nokia, 6.7% are self-published by Nokia as a CNA.

93.3%
Self-published: 10Published by other CNAs: 140

Trends Over Time

The number and severity of CVEs published by Nokia over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 17, 2024
21 months ago
Most Recent CVE
Jun 30, 2026
24 days ago

Top CVEs

All CVEs published by Nokia as a CNA, regardless of affected vendor or product.

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administrative (local admin) privileges can escalate to full root pri
Jun 30, 20267.833NONO
Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Successful exploitation could allow an authenticated attacker to
Jun 30, 20267.832NONO
Nokia MantaRay is subject to an Improper Access Control vulnerability due to insufficient authorization within the API. Successful exploitation could allow an authenticated attacke
Jun 30, 20266.530NONO
The CBIS/NCS Manager API is vulnerable to an authentication bypass. By sending a specially crafted HTTP header, an unauthenticated user can gain unauthorized access to API function
Sep 18, 20258.829NONO
The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD
Sep 18, 20258.428NONO
File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web applicati
Jul 21, 20259.028NONO
The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The vulnerable component is bound to the network stack and the se
Jul 21, 20259.028NONO
The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-level command execution. Due to
Feb 2, 20268.027NONO
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application.
Apr 7, 20268.026NONO
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.
Apr 7, 20268.026NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA26 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local10 (38.5%)
Network1 (3.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network15 (57.7%)
Attack Complexity
Low18 (69.2%)
High8 (30.8%)
Unknown0 (0.0%)
User Interaction
None25 (96.2%)
Unknown0 (0.0%)
Required1 (3.8%)
Privileges Required
Low14 (53.8%)
High11 (42.3%)
None1 (3.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Nokia as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Nokia as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs