CVE-2022-45899: Nokia Broadcast Message Center

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.

Affected products

  • Nokia Broadcast Message Center: before 13.1 (fixed in 13.1)

Published 2026-05-08. Last modified 2026-08-12.