First published: Tue Dec 17 2024(Updated: )
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_netaction.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded, potentially leading to unauthorized access to server permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Raisecom Msg1200 Firmware | ||
Raisecom Msg2100e Firmware | ||
Raisecom Msg2200 Firmware | ||
Raisecom Msg2300 Firmware | ||
All of | ||
Raisecom Msg2300 | =3.90 | |
Raisecom Msg2300 Firmware | ||
All of | ||
Raisecom Msg2100e Firmware | =3.90 | |
Raisecom Msg2100e Firmware | ||
All of | ||
Raisecom Msg2200 | =3.90 | |
Raisecom Msg2200 Firmware | ||
All of | ||
Raisecom Msg1200 Firmware | =3.90 | |
Raisecom Msg1200 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-55513 is classified as a high severity vulnerability due to the potential for unauthorized file uploads and access to server permissions.
To fix CVE-2024-55513, ensure that the affected web interface does not allow arbitrary file uploads and implement proper input validation.
CVE-2024-55513 affects Raisecom products including MSG1200, MSG2100E, MSG2200, and MSG2300.
The impact of CVE-2024-55513 includes the risk of unauthorized access and potential control over sensitive server functions due to file uploads.
A potential workaround for CVE-2024-55513 is to temporarily disable the file upload functionality until a patch is applied.