CVE-2021-26597
CVE-2021-26597 is a medium-severity vulnerability in Nokia Netact with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-434.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v2: 4.0
- EPSS exploit prediction: 1% (72nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-434
- Affected product: Nokia Netact
- Published:
- Last modified:
Description
An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.
Frequently asked questions
- What is CVE-2021-26597?
- An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.
- How severe is CVE-2021-26597?
- CVE-2021-26597 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2021-26597 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (72nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-26597?
- CVE-2021-26597 affects Nokia Netact. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-26597?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2021-26597 published?
- CVE-2021-26597 was published on 2021-03-25 and last updated on 2026-06-17.
References
Affected products (1)
- cpe:2.3:a:nokia:netact:18a:*:*:*:*:*:*:*
More vulnerabilities in Nokia Netact
- CVE-2022-30280 — High (CVSS 8.8): /SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with…
- CVE-2022-28864 — High (CVSS 8.8): An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user…
- CVE-2022-28863 — High (CVSS 8.8): An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site…
- CVE-2023-26059 — Medium (CVSS 6.8): An issue was discovered in Nokia NetAct before 22 SP1037. On the Site Configuration Tool tab, attackers can upload a…
- CVE-2023-26061 — Medium (CVSS 6.8): An issue was discovered in Nokia NetAct before 22 FP2211. On the Scheduled Search tab under the Alarm Reports Dashboard…
- CVE-2023-26060 — Medium (CVSS 6.8): An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working…
All CVEs affecting Nokia Netact →
Other CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities
- CVE-2026-39770 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions.
- CVE-2026-32579 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions.
- CVE-2026-102427 — Critical (CVSS 10.0): Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 -…
- CVE-2026-4357 — Critical (CVSS 10.0): The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as…
- CVE-2026-84147 — Critical (CVSS 10.0): This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation…
- CVE-2026-81780 — Critical (CVSS 10.0): Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.
Browse all CWE-434 (Unrestricted Upload of File with Dangerous Type) vulnerabilities →