PT-2024-20697 · Ericsson · Ericsson Ran Compute/Site Controller 6610
Published
2024-08-16
·
Updated
2024-08-19
·
CVE-2024-25008
CVSS v3.1
6.8
Medium
| Vector | AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ericsson RAN Compute and Site Controller 6610 versions prior to 24.Q2
Description
The issue is related to improper input validation in the Control System, which can lead to arbitrary code execution. For example, it can be used to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated privileges, such as a valid OAM user having the system administrator role, to exploit the issue.
Recommendations
For Ericsson RAN Compute and Site Controller 6610 versions prior to 24.Q2, upgrade the affected components immediately to mitigate threats.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ericsson Ran Compute/Site Controller 6610