A
ll versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.
References
| Link | Resource |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-01 | Patch Third Party Advisory US Government Resource |
| https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-01 | Patch Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
| AND |
|
History
21 Nov 2024, 07:20
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.6 |
| References | () https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-01 - Patch, Third Party Advisory, US Government Resource |
16 Sep 2024, 23:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device. |
Information
Published : 2022-11-10 22:15
Updated : 2024-11-21 07:20
NVD link : CVE-2022-3703
Mitre link : CVE-2022-3703
CVE.ORG link : CVE-2022-3703
JSON object : View
Products Affected
CWE
CWE-345
Insufficient Verification of Data Authenticity