High severity8.1NVD Advisory· Published Mar 3, 2026· Updated Jun 17, 2026
CVE-2021-35486
CVE-2021-35486
Description
A Cross-Site Request Forgery (CSRF) vulnerability in Nokia IMPACT through 19.11.2.10-20210118042150283 allows a remote attacker to import and overwrite the entire application configuration. Specifically, in /ui/rest-proxy/entity/import, neither the X-CSRF-NONCE HTTP header nor the CSRF-NONCE cookie is validated.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:nokia:impact_mobile:*:*:*:*:*:*:*:*Range: <=19.11.2.10-20210118042150283
- Range: <=19.11.2.10-20210118042150283
Patches
Vulnerability mechanics
References
3- www.gruppotim.it/it/footer/red-team/2021/Motive-Impact-CVE-2021-35486.htmlnvdThird Party Advisory
- www.nokia.com/notices/responsible-disclosure/nvdVendor Advisory
- www.nokia.com/networks/solutions/impact-iot-platform/nvdProduct
News mentions
0No linked articles in our index yet.