CVE-2024-48730 Details
Description
The default configuration in ETSI Open-Source MANO (OSM) v.14.x, v.15.x, v.16.x, v.17.x does not impose any restrictions on the authentication attempts performed by the default admin user, allowing a remote attacker to escalate privileges.
A vulnerability in ETSI Open-Source MANO (OSM) versions 14.x and 15.x allows remote attackers to escalate privileges by exploiting the lack of restrictions on authentication attempts for admin users. This flaw can be exploited to gain unauthorized access to administrative functions, potentially leading to full system compromise.
Users are advised to update to OSM MANO versions 14.0.3, 15.0.2, or 17.0.1. For version 16.0.0, a fix is available from a specific commit. Additionally, restrict access to the OSM interface to trusted users and implement request throttling and automated blacklisting for excessive or abnormal request patterns.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 25, 2025CISA-ADP
Assessed Jul 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.osmium.solutions/articles/osm-mano-vulnerability-discovery.html#2 | [email protected] | BundleExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| ETSI Open-Source MANO | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 18, 2025 | CVE Modified | [email protected] |
| Aug 18, 2025 | CVE Modified | [email protected] |
| Jul 25, 2025 | CVE Modified | CISA-ADP |
| Jul 25, 2025 | New CVE Received | [email protected] |
Volerion