The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD allows for command injection. These headers are directly utilized within the subprocess.Popen Python function without adequate validation, enabling a remote attacker to execute arbitrary commands on the underlying system by crafting malicious header values within an HTTP request to the affected endpoint. The web service executes with root privileges within the container environment, the demonstrated remote code execution permits an attacker to acquire elevated privileges for the command execution. Restricting access to the management network with an external firewall can partially mitigate this risk.
History

Thu, 18 Sep 2025 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Sep 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Nokia
Nokia cbis
Nokia ncs
Vendors & Products Nokia
Nokia cbis
Nokia ncs

Thu, 18 Sep 2025 06:15:00 +0000

Type Values Removed Values Added
Description The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD allows for command injection. These headers are directly utilized within the subprocess.Popen Python function without adequate validation, enabling a remote attacker to execute arbitrary commands on the underlying system by crafting malicious header values within an HTTP request to the affected endpoint. The web service executes with root privileges within the container environment, the demonstrated remote code execution permits an attacker to acquire elevated privileges for the command execution. Restricting access to the management network with an external firewall can partially mitigate this risk.
Title Remote Code Execution
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Nokia

Published: 2025-09-18T06:11:53.618Z

Updated: 2025-09-18T17:56:10.960Z

Reserved: 2023-11-27T09:09:46.615Z

Link: CVE-2023-49565

cve-icon Vulnrichment

Updated: 2025-09-18T17:52:55.437Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-18T06:15:34.720

Modified: 2025-09-18T18:15:37.353

Link: CVE-2023-49565

cve-icon Redhat

No data.