Nokia Network as Code · Vulnerability Disclosure

Nokia Network As Code Vulnerability Disclosure

Vulnerability disclosure

Nokia Network as Code runs a coordinated vulnerability disclosure program on Hackerone. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.

TelecommunicationsFinlandNetwork APIsCAMARAOpen GatewayNetwork API ExposureNetwork API Aggregator5GIdentity VerificationSIM SwapNumber VerificationDevice LocationQuality on DemandNetwork SlicingAnti-FraudKYCIoTeSIMRoamingNetwork Exposure
Program: Hackerone security.txt present

Disclosure Policy

Policy

Security Contact

Contact
security-alert@nokia.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-07-25'
method: searched
probe: true
source: >-
  https://www.nokia.com/.well-known/security.txt (HTTP 200, PGP-signed) and
  https://www.nokia.com/we-are-nokia/security/products/cvd/ (HTTP 200).
summary: >-
  The mechanical probe found nothing, because it looked at the product hosts -
  networkascode.nokia.io serves its SPA 404 for every /.well-known/ path and the
  RapidAPI gateway answers "API doesn't exists". The programme is at the
  corporate parent and it is a strong one: a named Coordinated Vulnerability
  Disclosure programme that explicitly covers "Nokia products and Nokia-hosted
  services" (which is what Network as Code is), a PGP-signed RFC 9116
  security.txt, a published PGP fingerprint, a researcher hall of fame, and CVE
  Numbering Authority status.
program: Nokia Coordinated Vulnerability Disclosure (CVD) Program
policy:
  - https://www.nokia.com/we-are-nokia/security/products/cvd/
contact:
  - security-alert@nokia.com
security_txt:
  url: https://www.nokia.com/.well-known/security.txt
  status: 200
  file: well-known/nokia-network-as-code-security.txt
  signed: true
  expires: '2036-12-31T23:00:00Z'
  preferred_languages: en
encryption:
  pgp_key: https://www.nokia.com/.well-known/nokia-public-key.asc
  fingerprint: B88A5B043A75E913D601F23ACBDD1EFF75E14178
acknowledgments: https://www.nokia.com/we-are-nokia/security/products/cvd/hall-of-fame/
advisories: https://www.nokia.com/we-are-nokia/security/product-security-advisory/
cna: true
cna_note: Nokia is a CVE Numbering Authority and may assign CVE IDs for confirmed vulnerabilities in actively supported products.
bug_bounty:
  paid: false
  note: >-
    No monetary bounty and no HackerOne / Bugcrowd / Intigriti presence was
    found. Recognition is via the hall of fame. Anonymous submissions are
    explicitly accepted.
scope_note: >-
  The CVD page states it is intended for security researchers not affiliated
  with Nokia customers; Nokia customers are directed to their customer team
  contact instead. Reports that are only automated scanner output or generic CVE
  notifications without reproduction steps are explicitly out of scope.
process:
  - Acknowledge receipt of the report.
  - Maintain communication throughout the investigation.
  - Determine resolution timelines based on severity and complexity.
  - Assign a CVE ID where the vulnerability affects an actively supported product.
evidence:
  - {source: 'https://www.nokia.com/.well-known/security.txt', kind: security.txt, status: 200}
  - {source: 'https://www.nokia.com/we-are-nokia/security/products/cvd/', kind: disclosure-policy, status: 200}
  - {source: well-known/nokia-network-as-code-security.txt, kind: harvested-file}
probe_results:
  - {url: 'https://networkascode.nokia.io/.well-known/security.txt', status: 404}
  - {url: 'https://developer.networkascode.nokia.io/.well-known/security.txt', status: 404}
  - {url: 'https://network-as-code.p-eu.rapidapi.com/.well-known/security.txt', status: 404, note: 'Declared as a real operation in the OpenAPI but gated behind the gateway API key.'}