CVE-2021-32570
About
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all must be previously defined and authorized by the Security Administrator. Those users can access some log’s files, under a common path, and read information stored in the log’s files in order to conduct privilege escalation.
Rainforest analyst review
A group of AMOS users on Ericsson Network Manager can read log files under a shared path, and those logs contain enough information to help one of them escalate privileges. The root cause is sensitive data landing in log files that a peer authorization group can reach. This is not an outsider problem — it's an insider or lateral-movement problem, where someone already inside the system mines logs for material that lifts them above their assigned tier.
The description is candid about the precondition: every AMOS user is already a highly privileged, security-administrator-vetted account. So the population that can exploit this is small, trusted, and named. That's why the score sits at medium rather than high — the flaw is real, but it presumes an authorized privileged user turning malicious or having their account compromised. It's a defense-in-depth failure, not a breach vector, and the impact is confidentiality of log contents that then aid escalation.
Our framing is to prioritize this below its face value and slot it into insider-risk and least-privilege work rather than emergency patching. Where ENM below 21.2 runs, we'd note it as a privilege-separation weakness worth closing on the normal maintenance cadence, and pair it with monitoring of who is reading those log paths. The people who can abuse it are already logged and authorized, which makes detection more tractable than prevention here.
References
Related CVEs
Frequently asked questions
What is CVE-2021-32570?
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files. All AMOS users are considered to be highly privileged users in ENM system and all must be previously defined and authorized by the Security Administrator.
How severe is CVE-2021-32570?
CVE-2021-32570 carries a CVSS 3.1 base score of 4.9, rated medium. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 52 out of 100, in the elevated band.
How is CVE-2021-32570 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N): attack vector Network, attack complexity Low, privileges required High, user interaction None. Impact on confidentiality High, integrity None and availability None.
Which products are affected by CVE-2021-32570?
Public advisories list the following as affected: network manager. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2021-32570?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
