CVE-2022-21215
CRITICALMimosa Management Platform < 1.0.3 - Server-Side Request Forgery
Title source: llmDescription
This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. The attacker could force the server into accessing routes on those cloud-hosting platforms, accessing secret keys, changing configurations, etc. Affecting MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1.
References (1)
Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsa-22-034-02
Scores
CVSS v3
10.0
EPSS
0.0139
EPSS Percentile
68.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-918
Status
published
Products (5)
airspan/a5x_firmware
< 2.5.4.1
airspan/c5c_firmware
< 2.8.6.1
airspan/c5x_firmware
< 2.8.6.1
airspan/c6x_firmware
< 2.8.6.1
airspan/mimosa_management_platform
< 1.0.3
Published
Feb 18, 2022
Tracked Since
Feb 18, 2026