PT-2024-5397 · Raisecom · Raisecom Msg2100E+3

H0E4A0R1T

·

Published

2024-08-04

·

Updated

2024-08-13

·

CVE-2024-7470

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 version 3.90
Description A critical issue affects the function sslvpn config mod of the file /vpn/vpn template style.php in the Web Interface component. The manipulation of the argument template/stylenum leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 version 3.90, as a temporary workaround, consider disabling the sslvpn config mod function until a patch is available. Restrict access to the /vpn/vpn template style.php file to minimize the risk of exploitation. Avoid using the template/stylenum argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06041
CVE-2024-7470

Affected Products

Raisecom Msg1200
Raisecom Msg2100E
Raisecom Msg2200
Raisecom Msg2300