PT-2024-5394 · Raisecom · Raisecom Msg2100E+3

H0E4A0R1T

·

Published

2024-08-04

·

Updated

2024-08-13

·

CVE-2024-7468

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 version 3.90
Description A critical issue affects the sslvpn config mod function of the /vpn/list service manage.php file in the Web Interface component. The manipulation of the template and stylenum arguments leads to OS command injection. This can be initiated remotely. The issue has been publicly disclosed and may be exploited.
Recommendations For Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 version 3.90, consider disabling the sslvpn config mod function as a temporary workaround until a patch is available. Restrict access to the /vpn/list service manage.php file to minimize the risk of exploitation. Avoid using the template and stylenum arguments in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-06038
CVE-2024-7468

Affected Products

Raisecom Msg1200
Raisecom Msg2100E
Raisecom Msg2200
Raisecom Msg2300