PT-2024-24054 · Clavister · Clavister E80+1
Strik3R
·
Published
2024-04-01
·
Updated
2024-05-17
·
CVE-2024-3141
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Clavister E10 and E80 versions up to 14.00.10
Description
A vulnerability has been found in the Misc Settings Page component, affecting the file /?Page=Node&OBJ=/System/AdvancedSettings/DeviceSettings/MiscSettings. The manipulation of the arguments
WatchdogTimerTime, BufFloodRebootTime, MaxPipeUsers, AVCache Lifetime, HTTPipeliningMaxReq, Reassembly MaxConnections, Reassembly MaxProcessingMem, and ScrSaveTime leads to cross-site scripting. The attack can be initiated remotely.Recommendations
For Clavister E10 and E80 versions up to 14.00.10, upgrade to version 14.00.11 to address this issue. As a temporary workaround, consider restricting access to the Misc Settings Page component until the upgrade is applied. Avoid using the vulnerable arguments in the affected file until the issue is resolved.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clavister E10
Clavister E80