Record summary

CVE-2022-45899 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.

Description

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2026 · Source: CVE List

Proofs of concept

1

Catalogued exploits

ExploitDBNokia BMC Log Scanner - Remote Code ExecutionExploitDB exploitby Carlos Andres Gonzalez_ Matthew GregoryNot analyzed1 file
ExploitDB

PoC details

References

3