CVE-2024-28806: High severity italtel i-mcs nfv vulnerability
Published Jul 29, 2024
·Updated
An issue was discovered in Italtel i-MCS NFV 12.1.0-20211215. Remote unauthenticated attackers can upload files at an arbitrary path.
Affected Software
2 affected components
Italtel i-MCS NFV
Italtel i-MCS NFV=12.1.0-20211215
Event History
Jul 29, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28806?
CVE-2024-28806 is considered to have a high severity due to the potential for remote unauthenticated attackers to exploit it.
2
How do I fix CVE-2024-28806?
To mitigate CVE-2024-28806, update to a patched version of Italtel i-MCS NFV or implement access controls to restrict file uploads.
3
What types of attacks are possible with CVE-2024-28806?
CVE-2024-28806 allows an attacker to upload files to arbitrary paths, which can lead to code execution or data exposure.
4
Is CVE-2024-28806 exploitable remotely?
Yes, CVE-2024-28806 can be exploited remotely without authentication by attackers.
5
Which version of Italtel i-MCS NFV is affected by CVE-2024-28806?
CVE-2024-28806 specifically affects Italtel i-MCS NFV version 12.1.0-20211215.