AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2021-28485

MEDIUM · CVSS 4.3 EPSS 0.55%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-09-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2021-28485
Severity
MEDIUM
CVSS
4.3
EPSS
0.55%

Original NVD Description

In Ericsson Mobile Switching Center Server (MSC-S) before IS 3.1 CP22, the SIS web application allows relative path traversal via a specific parameter in the https request after authentication, which allows access to files on the system that are not intended to be accessible via the web application.

Related CVEs

Other vulnerabilities affecting the same vendor(s)