CVE-2024-26157
ETIC Telecom Remote Access Server (RAS) Cross-site Scripting
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
17 ene 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0
are vulnerable to reflected cross site scripting (XSS) attacks in get
view method under view parameter. The ETIC RAS web server uses dynamic
pages that get their input from the client side and reflect the input in
their response to the client.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Productos afectados
ETIC Telecom · Remote Access Server (RAS)¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →