Impact
The vulnerability arises from an insufficient role‑based access control in the CPB Log Files feature of Nokia WaveSuite. An authenticated user with a low‑privilege role can bypass restrictions by directly entering the URL of a page that is intended for higher‑privilege roles. This flaw enables the attacker to view or download content, logs, or other sensitive information that should be protected, potentially exposing confidential operational data.
Affected Systems
Nokia WaveSuite is the affected product. No specific software or firmware versions are listed in the advisory, indicating that all current releases may be susceptible until a patch is released. The flaw specifically impacts the CPB Log Files feature used for viewing logs, but other restricted pages accessed through the same path are also vulnerable.
Risk and Exploitability
The CVSS score is 7.6 and the EPSS score is < 1%, but the flaw is known to allow privileged data exposure after authentication. Because the vulnerability requires a valid account, the attack vector is limited to authenticated users, yet it can still be exploited internally by any low‑privilege user. The lack of a KEV listing suggests no public exploits yet, but administrators should treat it as a moderate‑to‑high risk until a vendor fix becomes available.
OpenCVE Enrichment