PT-2024-29637 · Unknown · Ons-S8 - Spectra Aggregation Switch

Published

2024-10-01

·

Updated

2024-10-15

·

CVE-2024-41925

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ONS-S8 - Spectra Aggregation Switch (affected versions not specified)
Description The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass authentication, and execute remote code. This issue is being actively exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-41925

Affected Products

Ons-S8 - Spectra Aggregation Switch