The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD allows for command injection. These headers are directly utilized within the subprocess.Popen Python function without adequate validation, enabling a remote attacker to execute arbitrary commands on the underlying system by crafting malicious header values within an HTTP request to the affected endpoint.
The web service executes with root privileges within the container environment, the demonstrated remote code execution permits an attacker to acquire elevated privileges for the command execution.
Restricting access to the management network with an external firewall can partially mitigate this risk.
Metrics
Affected Vendors & Products
References
History
Thu, 18 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 | |
Metrics |
cvssV3_1
|
Thu, 18 Sep 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nokia
Nokia cbis Nokia ncs |
|
Vendors & Products |
Nokia
Nokia cbis Nokia ncs |
Thu, 18 Sep 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sanitization of the HTTP Headers X-FILENAME, X-PAGE, and X-FIELD allows for command injection. These headers are directly utilized within the subprocess.Popen Python function without adequate validation, enabling a remote attacker to execute arbitrary commands on the underlying system by crafting malicious header values within an HTTP request to the affected endpoint. The web service executes with root privileges within the container environment, the demonstrated remote code execution permits an attacker to acquire elevated privileges for the command execution. Restricting access to the management network with an external firewall can partially mitigate this risk. | |
Title | Remote Code Execution | |
References |
|

Status: PUBLISHED
Assigner: Nokia
Published: 2025-09-18T06:11:53.618Z
Updated: 2025-09-18T17:56:10.960Z
Reserved: 2023-11-27T09:09:46.615Z
Link: CVE-2023-49565

Updated: 2025-09-18T17:52:55.437Z

Status : Awaiting Analysis
Published: 2025-09-18T06:15:34.720
Modified: 2025-09-18T18:15:37.353
Link: CVE-2023-49565

No data.