Ericssonlg produces telecommunications and enterprise communications infrastructure, with its vulnerability footprint centered on the iPECS unified communications platform and associated network management systems. The observed weakness classes—path traversal, SQL injection, default and incorrect permissions, and credential protection gaps—reflect recurrent input-validation and access-control gaps characteristic of legacy enterprise infrastructure software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ericssonlg over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10285CRITICAL The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication | Apr 22, 2018 | 9.8 | 47 | NO | YES |
CVE-2018-9245CRITICAL The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code | Apr 22, 2018 | 9.8 | 42 | NO | YES |
CVE-2018-15138HIGH Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs. | Aug 15, 2018 | 7.5 | 40 | NO | YES |
CVE-2018-10286HIGH The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the | Apr 22, 2018 | 8.8 | 40 | NO | YES |
CVE-2020-7824MEDIUM A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission. The vulnerability is due to insecure p | Aug 25, 2020 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ericssonlg.
Media articles that mention a CVE ID that affects a product developed by Ericssonlg — matched by CVE ID, not by vendor name.