PT-2024-8126 · Eltex · Eltex Mes5324

Published

2024-09-13

·

Updated

2024-09-13

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Eltex MES5324 (affected versions not specified)
Description: The issue is related to insufficient input validation in the web interface of the Eltex MES5324 switch's firmware management. An attacker can exploit this by sending specially crafted HTTP GET requests, potentially allowing a remote attacker to cause the switch to reboot.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09665

Affected Products

Eltex Mes5324