CVE-2024-55513: Path Traversal
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /uploadnetaction.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55513?
CVE-2024-55513 is classified as a high severity vulnerability due to the potential for unauthorized file uploads and access to server permissions.
How do I fix CVE-2024-55513?
To fix CVE-2024-55513, ensure that the affected web interface does not allow arbitrary file uploads and implement proper input validation.
What products are affected by CVE-2024-55513?
CVE-2024-55513 affects Raisecom products including MSG1200, MSG2100E, MSG2200, and MSG2300.
What impact does CVE-2024-55513 have on security?
The impact of CVE-2024-55513 includes the risk of unauthorized access and potential control over sensitive server functions due to file uploads.
Is there a workaround for CVE-2024-55513?
A potential workaround for CVE-2024-55513 is to temporarily disable the file upload functionality until a patch is applied.