SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-24817

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.

HIGH 8.0EPSS 1.01%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.

CVSS 3.1
8.0 HIGHCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.01% probability · 61th percentile
CISA KEV
Not listed
Weakness
CWE-78
Affected
nokia/mantaray nm
Source
b48c3b8f-639e-4c16-8725-497bc411dad0

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.