PT-2022-25651 · Etic Telecom · Etic Telecom Remote Access Server
Published
2022-11-10
·
Updated
2024-09-17
·
CVE-2022-40981
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ETIC Telecom Remote Access Server (RAS) versions 4.5.0 and prior
Description
The issue allows for malicious file upload, which an attacker could exploit to store malicious files on the server. This could result in overriding sensitive files on the filesystem, filling the hard disk to full capacity, or compromising the affected device or connected computers with administrator-level privileges.
Recommendations
For versions 4.5.0 and prior, consider disabling file upload functionality until a patch is available to prevent malicious file uploads. Restrict access to sensitive files and directories on the server to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Etic Telecom Remote Access Server