PT-2024-32879 · Intermesh · Intermesh 7707 Fire Subscriber+1
Published
2024-10-23
·
Updated
2024-10-30
·
CVE-2024-47903
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
InterMesh 7177 Hybrid 2.0 Subscriber versions prior to 8.2.12
InterMesh 7707 Fire Subscriber versions prior to 7.2.12
Description
A vulnerability has been identified that allows writing arbitrary files to the web server's DocumentRoot directory. This issue affects devices where the IP interface is enabled, which is not the default configuration.
Recommendations
For InterMesh 7177 Hybrid 2.0 Subscriber versions prior to 8.2.12, update to version 8.2.12 or later.
For InterMesh 7707 Fire Subscriber versions prior to 7.2.12 with the IP interface enabled, update to version 7.2.12 or later and consider disabling the IP interface until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Intermesh 7177 Hybrid 2.0 Subscriber
Intermesh 7707 Fire Subscriber