CVE-2022-40981
ETIC Telecom Remote Access Server Unrestricted Upload of File with Dangerous Type
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.9EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
10 nov 2022Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior is vulnerable to malicious file upload. An attacker could take advantage of this to store malicious files on the server, which could override sensitive and useful existing files on the filesystem, fill the hard disk to full capacity, or compromise the affected device or computers with administrator level privileges connected to the affected device.
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Productos afectados
ETIC Telecom · Remote Access Server (RAS)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →