CVE-2024-7468: Raisecom MSG1200/MSG2100E/MSG2200/MSG2300 Web Interface list_service_manage.php sslvpn_config_mod os command injection
A vulnerability was found in Raisecom MSG1200, MSG2100E, MSG2200 and MSG2300 3.90. It has been classified as critical. This affects the function sslvpnconfigmod of the file /vpn/listservicemanage.php of the component Web Interface. The manipulation of the argument template/stylenum leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-273561 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7468?
CVE-2024-7468 has been classified as a critical severity vulnerability.
Which devices are affected by CVE-2024-7468?
CVE-2024-7468 affects Raisecom MSG1200, MSG2100E, MSG2200, and MSG2300, all running firmware version 3.90.
How do I fix CVE-2024-7468?
To fix CVE-2024-7468, update the affected Raisecom devices to the latest firmware version provided by the manufacturer.
What component is affected in CVE-2024-7468?
The vulnerability CVE-2024-7468 affects the sslvpn_config_mod function in the Web Interface of the affected devices.
What impact does CVE-2024-7468 have on affected systems?
CVE-2024-7468 could allow unauthorized manipulation of certain arguments, potentially compromising the affected systems.