CVE-2025-24817
8.0Nokia · MantaRay NM
Nokia MantaRay NM contains an OS command injection vulnerability in the Symptom Collector application due to improper neutralization of command elements.
Executive summary
A critical OS command injection vulnerability in Nokia MantaRay NM could allow an authenticated attacker with low privileges to execute arbitrary commands on the underlying system.
Vulnerability
The vulnerability exists within the Symptom Collector application, where improper neutralization of input allows for OS command injection. Per the CVSS vector (PR:L), this requires a low-privilege authenticated user to trigger the flaw.
Business impact
The ability to inject and execute arbitrary OS commands poses a severe threat to the confidentiality, integrity, and availability of the affected system. Successful exploitation could lead to full system compromise, unauthorized data access, or the disruption of critical network management services. With a CVSS score of 8.0, this vulnerability is classified as High severity and warrants immediate attention to prevent potential lateral movement or persistent unauthorized access.
Remediation
Immediate Action: Update Nokia MantaRay NM to version 25R1-NM or later to resolve the vulnerability.
Proactive Monitoring: Review system access logs for unusual command execution patterns or unauthorized attempts to access the Symptom Collector utility.
Compensating Controls: Restrict network access to the management interface to trusted administrative segments only to reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high impact of OS command injection vulnerabilities, organizations running Nokia MantaRay NM should prioritize upgrading to the patched version as soon as it becomes available. Administrators must verify that access controls are strictly enforced to prevent low-privilege users from reaching the vulnerable Symptom Collector application until the update is applied.