CVE-2023-49564 Details
Description
The CBIS/NCS Manager API is vulnerable to an authentication bypass. By sending a specially crafted HTTP header, an unauthenticated user can gain unauthorized access to API functions. This flaw allows attackers to reach restricted or sensitive endpoints of the HTTP API without providing any valid credentials. The root cause of this vulnerability lies in a weak verification mechanism within the authentication implementation present in the Nginx Podman container on the CBIS/NCS Manager host machine. The risk can be partially mitigated by restricting access to the management network using external firewall.
An authentication bypass vulnerability has been identified in the CBIS/NCS Manager API, specifically in CBIS 22 and NCS 22.12. This vulnerability allows unauthenticated users to access restricted API functions by sending a specially crafted HTTP header. The issue arises from a weak authentication verification mechanism in the Nginx Podman container on the CBIS/NCS Manager host machine. As a result, attackers can reach sensitive endpoints of the HTTP API without valid credentials.
Users can upgrade to CBIS 22 FP1 MP1.2 or NCS 22.12 MP3 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2025CISA-ADP
Assessed Sep 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nokia.com/about-us/security-and-privacy/product-security-advisory/CVE-2023-49564/ | Nokia | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-288 | Authentication Bypass Using an Alternate Path or Channel | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Nokia CloudBand Infrastructure Software | All versions |
CPE
Remediation
| |
| Nokia Container Service | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Nokia |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2025 | CVE Modified | CISA-ADP |
| Sep 18, 2025 | New CVE Received | Nokia |
Volerion