CVE-2024-26154

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Jan 17, 2025
CWE ID 79

Summary

CVE-2024-26154 is a newly disclosed cross-site scripting (XSS) vulnerability affecting all versions of ETIC Telecom Remote Access Server (RAS) before 4.5.0. The issue lies within the appliance site name functionality, where user-supplied input is not adequately sanitized before being displayed to administrators on various pages. Attackers can exploit this XSS vulnerability by injecting malicious scripts through the site name input field, potentially gaining unauthorized access to administrator sessions or stealing sensitive information. Upgrading to RAS version 4.5.0 or later is recommended to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share