PT-2024-5395 · Raisecom · Raisecom Msg2100E+3

H0E4A0R1T

·

Published

2024-08-04

·

Updated

2024-08-13

·

CVE-2024-7467

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 version 3.90
Description A critical issue affects the sslvpn config mod function of the /vpn/list ip network.php file in the Web Interface component. The manipulation of the template and stylenum arguments leads to os command injection. This issue can be exploited remotely.
Recommendations For Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 version 3.90, as a temporary workaround, consider disabling the sslvpn config mod function until a patch is available. Restrict access to the /vpn/list ip network.php file to minimize the risk of exploitation. Avoid using the template and stylenum arguments in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-06039
CVE-2024-7467

Affected Products

Raisecom Msg1200
Raisecom Msg2100E
Raisecom Msg2200
Raisecom Msg2300