PT-2024-38894 · Teltonika Networks · Rutos+1
Published
2024-12-10
·
Updated
2024-12-10
·
CVE-2024-8256
CVSS v4.0
5.9
Medium
| Vector | AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
Teltonika Networks RUTOS versions 7.0 through 7.7
Teltonika Networks TSWOS versions 1.0 through 1.2
Description:
A vulnerability exists due to incorrect permission handling, allowing a lower privileged user with default permissions to access critical device resources via the API.
Recommendations:
For Teltonika Networks RUTOS versions 7.0 through 7.7, consider restricting access to critical device resources until a patch is available.
For Teltonika Networks TSWOS versions 1.0 through 1.2, consider disabling API access for lower privileged users with default permissions until a fix is released.
As a temporary workaround, consider limiting the use of the API to minimize the risk of exploitation.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rutos
Tswos