PT-2024-24054 · Clavister · Clavister E80+1

Strik3R

·

Published

2024-04-01

·

Updated

2024-05-17

·

CVE-2024-3141

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Clavister E10 and E80 versions up to 14.00.10
Description A vulnerability has been found in the Misc Settings Page component, affecting the file /?Page=Node&OBJ=/System/AdvancedSettings/DeviceSettings/MiscSettings. The manipulation of the arguments WatchdogTimerTime, BufFloodRebootTime, MaxPipeUsers, AVCache Lifetime, HTTPipeliningMaxReq, Reassembly MaxConnections, Reassembly MaxProcessingMem, and ScrSaveTime leads to cross-site scripting. The attack can be initiated remotely.
Recommendations For Clavister E10 and E80 versions up to 14.00.10, upgrade to version 14.00.11 to address this issue. As a temporary workaround, consider restricting access to the Misc Settings Page component until the upgrade is applied. Avoid using the vulnerable arguments in the affected file until the issue is resolved.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-3141

Affected Products

Clavister E10
Clavister E80