medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2015-2166 Scanner

CVE-2015-2166 scanner - Directory Traversal vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP)

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-2166
5.0
CVSS

Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the default URI.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 18, 2026View on NVD →
Detail

The Ericsson Drutt Mobile Service Delivery Platform (MSDP) is a software solution that helps telecommunications companies manage mobile services delivery. It is a high-performance platform designed to support operators in delivering value-added services such as streaming video, mobile gaming, and other revenue-generating services. The platform features a modular architecture, enabling customization and easy integration with existing systems.

The CVE-2015-2166 vulnerability is a directory traversal vulnerability in the Instance Monitor component of Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6. This vulnerability allows remote attackers to read any arbitrary files by including %2f (dot dot encoded slash) in the default URI. The vulnerability was discovered in 2015 and was assigned a Common Vulnerabilities and Exposures (CVE) ID of CVE-2015-2166.

Exploiting this vulnerability can lead to unauthorized access to sensitive data, including login credentials, personal information of customers, and business-critical data. An attacker could use this vulnerability to gain administrative access to the Ericsson Drutt Mobile Service Delivery Platform (MSDP) and launch further attacks, including data theft, compromised system integrity, and launching malware or ransomware attacks.

In addition to reading about the CVE-2015-2166 vulnerability in Ericsson Drutt Mobile Service Delivery Platform (MSDP), you can easily and quickly learn about vulnerabilities in your own digital assets by using the pro features of the s4e.io platform. Our platform provides real-time alerts for vulnerabilities, proactive threat intelligence, and 24/7 customer support to ensure the security and integrity of your digital assets.

 

REFERENCES

Solution Advice

To protect against the CVE-2015-2166 vulnerability, it is recommended to apply the latest security patches and updates provided by Ericsson. Additionally, the following precautions can be taken:

  • Implement proper access controls and authorization mechanisms.
  • Disable any unnecessary services or ports.
  • Take regular backups of critical data in case of a breach or data loss.
  • Implement network-level security controls, such as firewalls, intrusion detection and prevention systems (IDPS), and antivirus solutions.
  • Conduct regular vulnerability assessments and penetration testing to identify and address security gaps.
     

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.