Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 13 Mar 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nokia impact Mobile
|
|
| CPEs | cpe:2.3:a:nokia:impact_mobile:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nokia impact Mobile
|
Wed, 04 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Wed, 04 Mar 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nokia
Nokia impact |
|
| Vendors & Products |
Nokia
Nokia impact |
Tue, 03 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor the CSRF-NONCE cookie is validated. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-03-04T15:16:03.968Z
Reserved: 2021-06-24T00:00:00.000Z
Link: CVE-2021-35486
Updated: 2026-03-04T15:14:11.245Z
Status : Analyzed
Published: 2026-03-03T18:16:21.050
Modified: 2026-03-13T01:04:48.307
Link: CVE-2021-35486
No data.
OpenCVE Enrichment
Updated: 2026-03-04T14:54:59Z