Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Nokia CBIS/NCS Manager API Vulnerability Let Attackers Bypass Authentication

Nokia CBIS/NCS Manager API Vulnerability Let Attackers Bypass Authentication

Posted on September 19, 2025September 19, 2025 By CWS

A crucial authentication bypass vulnerability has emerged in Nokia’s CloudBand Infrastructure Software program (CBIS) and Nokia Container Service (NCS) Supervisor API, designated as CVE-2023-49564.

This high-severity flaw, scoring 9.6 on the CVSS v3.1 scale, allows unauthorized attackers to bypass authentication mechanisms via specifically crafted HTTP headers, doubtlessly granting full entry to restricted API endpoints with out legitimate credentials.

The vulnerability impacts CBIS 22 and NCS 22.12 variations, impacting enterprises, service suppliers, and public sector organizations using Nokia’s cloud and community infrastructure options.

The flaw was publicly disclosed on September 18, 2025, following discovery by Orange Cert researchers who recognized the safety hole throughout routine safety assessments.

Nokia safety researchers recognized the foundation trigger as a weak verification mechanism embedded inside the authentication implementation of the Nginx Podman container operating on the CBIS/NCS Supervisor host machine.

This architectural weak point permits risk actors to govern HTTP header fields to trick the authentication system into believing a request is legit.

The exploitation vector requires adjoining community entry (CVSS AV:A), making it significantly regarding for enterprise environments the place attackers may have already got gained preliminary community foothold.

As soon as exploited, the vulnerability supplies full compromise capabilities with excessive confidentiality, integrity, and availability impression, permitting attackers to entry delicate configuration information, modify system settings, and doubtlessly disrupt community operations.

Technical Assault Mechanism

The authentication bypass operates via header manipulation focusing on the Nginx container’s verification logic.

When processing API requests, the system fails to correctly validate authentication tokens embedded in HTTP headers, creating a chance for crafted requests to bypass safety controls.

The vulnerability permits unauthenticated customers to succeed in delicate endpoints that ought to require administrative privileges.

Vulnerability DetailsInformationCVE IDCVE-2023-49564CVSS Score9.6 (Essential)Assault VectorAdjacent NetworkAffected ProductsCBIS 22, NCS 22.12Fix VersionsCBIS 22 FP1 MP1.2, NCS 22.12 MP3

Organizations can partially mitigate dangers by implementing exterior firewall restrictions on administration community entry whereas making use of the patches offered in CBIS 22 FP1 MP1.2 and NCS 22.12 MP3 variations.

Discover this Story Attention-grabbing! Comply with us on Google Information, LinkedIn, and X to Get Extra Instantaneous Updates.

Cyber Security News Tags:API, Attackers, Authentication, Bypass, CBISNCS, Manager, Nokia, Vulnerability

Post navigation

Previous Post: Russian Hacking Groups Gamaredon and Turla Attacking Organizations to Deploy Kazuar Backdoor
Next Post: Top 10 Best API Security Testing Tools in 2025

Related Posts

China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware Cyber Security News
Ukraine Police Exposed Russian Hacker Group Specializes in Ransomware Attack Ukraine Police Exposed Russian Hacker Group Specializes in Ransomware Attack Cyber Security News
Cybersecurity News Weekly Newsletter – Windows, Chrome, and Apple 0-days, Kali Linux 2025.4, and MITRE Top 25 Cybersecurity News Weekly Newsletter – Windows, Chrome, and Apple 0-days, Kali Linux 2025.4, and MITRE Top 25 Cyber Security News
Palo Alto Networks Firewall Vulnerability Allows Unauthenticated Attackers to Trigger Denial of Service Palo Alto Networks Firewall Vulnerability Allows Unauthenticated Attackers to Trigger Denial of Service Cyber Security News
Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks Cyber Security News
UK Introduces Passkeys for 23 Million GOV.UK Users UK Introduces Passkeys for 23 Million GOV.UK Users Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark