CVE-2024-25011

MEDIUM

Ericsson Catalog Manager/Ericsson Order Care - Info Disclosure

Title source: llm
STIX 2.1

Description

Ericsson Catalog Manager and Ericsson Order Care APIs do not have authentication enabled by default. Authentication checks can be configured to remediate the information disclosure issue.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0026
EPSS Percentile 16.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
Ericsson/Ericsson Catalog Manager < 22.6
Ericsson/Ericsson Order Care < 22.6
Published Sep 18, 2025
Tracked Since Feb 18, 2026