Ericsson Network Manager (ENM) before 21.2 has incorrect access-control behavior (that only affects the level of access available to persons who were already granted a highly privileged role). Users in the same AMOS authorization group can retrieve managed-network data that was not set to be accessible to the entire group (i.e., was only set to be accessible to a subset of that group).
Use CWE-668, Ericsson vendor hub and Network Manager product page to widen CVE-2021-28488 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-39909, CVE-2024-25007 and CVE-2025-27258 for nearby disclosures in the same product family. Additional editorial context is available in Why “Low” and “Medium” CVEs Still Breach Networks.