CVE-2022-41763: Nokia Access Management System
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the service.
Affected products
- Nokia Access Management System: version 9.7.05 only
Published 2023-09-05. Last modified 2026-06-17.