CVE 9 CRITICAL

Access to local file system and its content_CVE-2025-24937

9 / 10
CRITICAL
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

File contents could be read from the local file system by an attacker. Additionally, malicious code could be inserted in the file, leading to a full compromise of the web application and the container it is running on.

The vulnerable component is bound to the network stack and the set of possible attackers extends up to and including the entire Internet. The web application allows arbitrary files to be included in a file that was downloadable and executable by the web server.

Basic Information

ID CVE-2025-24937
Source Nokia
Published Jul 21, 2025 at 06:31
Modified Jul 23, 2025 at 18:43

Affected Product

Vendor Nokia
Product WaveSuite NOC
Version WS-NOC 24.6, WS-NOC 23.6 and WS-NOC 23.12
Affected Versions Nokia WaveSuite NOC WS-NOC 24.6, WS-NOC 23.6 and WS-NOC 23.12

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.