CVE-2023-49564 describes an authentication bypass vulnerability in the CBIS/NCS Manager API, specifically within the Nginx Podman container on the host machine. An unauthenticated attacker can gain full access to API functions by sending a specially crafted HTTP header, bypassing credential checks. This flaw carries a CVSS score of 8.8 (High), indicating a critical risk due to its low attack complexity (AV:A/AC:L) and high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed in CISA's KEV catalog, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Nokia | CBIS,NCS | CBIS 22, NCS 22.12CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.