6.3

CVE-2024-55514

A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_sfmig.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RaisecomMsg2300 Firmware Version3.90
   RaisecomMsg2300 Version-
RaisecomMsg2100e Firmware Version3.90
   RaisecomMsg2100e Version-
RaisecomMsg2200 Firmware Version3.90
   RaisecomMsg2200 Version-
RaisecomMsg1200 Firmware Version3.90
   RaisecomMsg1200 Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.125
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.3 2.8 3.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

https://gist.github.com/wscg928/cbe88078751abad2ada2334eb12a5060
Third Party Advisory