First published: Tue Dec 17 2024(Updated: )
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 3.90. The component affected by this issue is /upload_ipslib.php on the web interface. By crafting a suitable form name, arbitrary files can be uploaded.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Raisecom Msg1200 Firmware | ||
Raisecom Msg2100e Firmware | ||
Raisecom Msg2200 Firmware | ||
Raisecom Msg2300 Firmware | ||
All of | ||
Raisecom Msg2300 | =3.90 | |
Raisecom Msg2300 Firmware | ||
All of | ||
Raisecom Msg2100e Firmware | =3.90 | |
Raisecom Msg2100e Firmware | ||
All of | ||
Raisecom Msg2200 | =3.90 | |
Raisecom Msg2200 Firmware | ||
All of | ||
Raisecom Msg1200 Firmware | =3.90 | |
Raisecom Msg1200 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-55515 has a high severity rating due to its ability to allow arbitrary file uploads on the affected devices.
To fix CVE-2024-55515, update to the latest firmware version provided by Raisecom for the impacted MSG1200, MSG2100E, MSG2200, or MSG2300 models.
CVE-2024-55515 affects Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300 devices running firmware version 3.90.
CVE-2024-55515 can be exploited through arbitrary file uploads, allowing attackers to potentially execute malicious files on the device.
To mitigate risks from CVE-2024-55515, restrict access to the web interface and regularly apply security updates from Raisecom.