PT-2024-36539 · Raisecom · Raisecom Msg2100E+3
Wscg928
·
Published
2024-12-17
·
Updated
2024-12-18
·
CVE-2024-55515
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Raisecom MSG1200 version 3.90
Raisecom MSG2100E version 3.90
Raisecom MSG2200 version 3.90
Raisecom MSG2300 version 3.90
Description
A problem exists in the web interface of the affected devices, specifically in the /upload ipslib.php component. By crafting a suitable form name, an attacker can upload arbitrary files.
Recommendations
For Raisecom MSG1200 version 3.90, consider disabling access to the /upload ipslib.php endpoint until a patch is available.
For Raisecom MSG2100E version 3.90, restrict the ability to upload files through the web interface as a temporary workaround.
For Raisecom MSG2200 version 3.90, avoid using the vulnerable component /upload ipslib.php until the issue is resolved.
For Raisecom MSG2300 version 3.90, as a temporary measure, limit access to the web interface to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Raisecom Msg1200
Raisecom Msg2100E
Raisecom Msg2200
Raisecom Msg2300