PT-2024-36538 · Raisecom · Raisecom Msg2100E+3

Wscg928

·

Published

2024-12-17

·

Updated

2024-12-18

·

CVE-2024-55514

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Raisecom MSG1200 version 3.90 Raisecom MSG2100E version 3.90 Raisecom MSG2200 version 3.90 Raisecom MSG2300 version 3.90
Description A vulnerability was found in the web interface of Raisecom devices, specifically in the /upload sfmig.php component. By crafting a suitable form name, an attacker can upload arbitrary files, potentially leading to unauthorized access to server permissions.
Recommendations For Raisecom MSG1200 version 3.90, consider disabling the /upload sfmig.php component until a patch is available. For Raisecom MSG2100E version 3.90, restrict access to the /upload sfmig.php component to minimize the risk of exploitation. For Raisecom MSG2200 version 3.90, avoid using the vulnerable form name in the /upload sfmig.php component until the issue is resolved. For Raisecom MSG2300 version 3.90, consider applying configuration changes to limit the upload of arbitrary files in the /upload sfmig.php component.

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-55514

Affected Products

Raisecom Msg1200
Raisecom Msg2100E
Raisecom Msg2200
Raisecom Msg2300