CVE-2021-43339
HIGHEricsson Network Location <2021-07-31 - Command Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2021-43339. PoCs published by AkkuS.
AI-analyzed exploit summary This Metasploit module exploits a privilege escalation vulnerability in Ericsson Network Location Mobile Positioning Systems by leveraging stolen PostgreSQL credentials to create a new admin user via SQL injection. The exploit uses a series of encoded payloads to bypass restrictions and execute commands.
Description
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created.
Exploits (2)
This Metasploit module exploits a privilege escalation vulnerability in Ericsson Network Location Mobile Positioning Systems by leveraging stolen PostgreSQL credentials to create a new admin user via SQL injection. The exploit uses a series of encoded payloads to bypass restrictions and execute commands.
This Metasploit module exploits a command injection vulnerability in Ericsson Network Location Mobile Positioning Systems via the 'file_name' parameter in export functionality. It bypasses restrictions to achieve remote code execution (RCE) on vulnerable systems.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H