All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-01 | Patch Third Party Advisory US Government Resource |
Configurations
Information
Published : 2022-11-10 14:15
Updated : 2022-11-16 06:58
NVD link : CVE-2022-3703
Mitre link : CVE-2022-3703
JSON object : View
CWE
CWE-345
Insufficient Verification of Data Authenticity
Products Affected
etictelecom
- remote_access_server