Italtel manufactures telecommunications and network infrastructure products including the Embrace platform, I-MCS NFV middleware, and NetMatch switching appliances, which serve telecom operators and enterprise networks. The vendor's vulnerability profile is characterized by serious-severity outcomes across its portfolio and recurs through web-application and access-control weaknesses—cross-site scripting, improper access control, path traversal, and cleartext transmission of sensitive data—that are typical of legacy network management interfaces and provisioning systems. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Italtel over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39811CRITICAL Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not verifying permissions for access | Jan 27, 2023 | 9.1 | 28 | NO | NO |
CVE-2024-28805CRITICAL An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. There is Incorrect Access Control. | Jul 29, 2024 | 9.1 | 25 | NO | NO |
CVE-2022-39812HIGH Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthenticated user can upload files to an arbitrary path. An attacker | Jan 27, 2023 | 7.5 | 25 | NO | NO |
CVE-2024-31842HIGH An issue was discovered in Italtel Embrace 1.6.4. The web application inserts the access token of an authenticated user inside GET requests. The query string for the URL could be s | Aug 20, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-28804HIGH An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Stored Cross-site scripting (XSS) can occur via POST. | Jul 29, 2024 | 7.1 | 21 | NO | NO |
CVE-2022-39813MEDIUM Italtel NetMatch-S CI 5.2.0-20211008 allows Multiple Reflected/Stored XSS issues under NMSCIWebGui/j_security_check via the j_username parameter, or NMSCIWebGui/actloglineview.jsp | Jan 27, 2023 | 6.1 | 21 | NO | NO |
CVE-2024-31846HIGH An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor. | Apr 19, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-31841HIGH An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem. | Apr 19, 2024 | 7.5 | 20 | NO | NO |
CVE-2024-28806HIGH An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path. | Jul 29, 2024 | 7.5 | 19 | NO | NO |
CVE-2024-31840MEDIUM An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration o | May 21, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Italtel.
Media articles that mention a CVE ID that affects a product developed by Italtel — matched by CVE ID, not by vendor name.