CVE-2024-55515: Path Traversal
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /uploadipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-55515?
CVE-2024-55515 has a high severity rating due to its ability to allow arbitrary file uploads on the affected devices.
How do I fix CVE-2024-55515?
To fix CVE-2024-55515, update to the latest firmware version provided by Raisecom for the impacted MSG1200, MSG2100E, MSG2200, or MSG2300 models.
What devices are affected by CVE-2024-55515?
CVE-2024-55515 affects Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 devices running firmware version 3.90.
What type of attack can exploit CVE-2024-55515?
CVE-2024-55515 can be exploited through arbitrary file uploads, allowing attackers to potentially execute malicious files on the device.
How can I mitigate risks associated with CVE-2024-55515?
To mitigate risks from CVE-2024-55515, restrict access to the web interface and regularly apply security updates from Raisecom.