PT-2022-25651 · Etic Telecom · Etic Telecom Remote Access Server

Published

2022-11-10

·

Updated

2024-09-17

·

CVE-2022-40981

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ETIC Telecom Remote Access Server (RAS) versions 4.5.0 and prior
Description The issue allows for malicious file upload, which an attacker could exploit to store malicious files on the server. This could result in overriding sensitive files on the filesystem, filling the hard disk to full capacity, or compromising the affected device or connected computers with administrator-level privileges.
Recommendations For versions 4.5.0 and prior, consider disabling file upload functionality until a patch is available to prevent malicious file uploads. Restrict access to sensitive files and directories on the server to minimize the risk of exploitation.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2022-40981

Affected Products

Etic Telecom Remote Access Server