10
CVE-2022-3703
- EPSS 0.29%
- Veröffentlicht 10.11.2022 22:15:14
- Zuletzt bearbeitet 21.11.2024 07:20:04
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
ETIC Telecom Remote Access Server Insufficient Verification of Data Authenticity
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Etictelecom ≫ Remote Access Server Firmware Version <= 4.5.0
Etictelecom ≫ Ras-c-100-lw Version-
Etictelecom ≫ Ras-e-100 Version-
Etictelecom ≫ Ras-e-220 Version-
Etictelecom ≫ Ras-e-400 Version-
Etictelecom ≫ Ras-ec-220-lw Version-
Etictelecom ≫ Ras-ec-400-lw Version-
Etictelecom ≫ Ras-ec-480-lw Version-
Etictelecom ≫ Ras-ecw-220-lw Version-
Etictelecom ≫ Ras-ecw-400-lw Version-
Etictelecom ≫ Ras-ew-100 Version-
Etictelecom ≫ Ras-ew-220 Version-
Etictelecom ≫ Ras-ew-400 Version-
Etictelecom ≫ Rfm-e Version-
Etictelecom ≫ Ras-e-100 Version-
Etictelecom ≫ Ras-e-220 Version-
Etictelecom ≫ Ras-e-400 Version-
Etictelecom ≫ Ras-ec-220-lw Version-
Etictelecom ≫ Ras-ec-400-lw Version-
Etictelecom ≫ Ras-ec-480-lw Version-
Etictelecom ≫ Ras-ecw-220-lw Version-
Etictelecom ≫ Ras-ecw-400-lw Version-
Etictelecom ≫ Ras-ew-100 Version-
Etictelecom ≫ Ras-ew-220 Version-
Etictelecom ≫ Ras-ew-400 Version-
Etictelecom ≫ Rfm-e Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.204 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 3.9 | 6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
|
| ics-cert@hq.dhs.gov | 7.6 | 1 | 6 |
CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-01