CVE-2024-26154
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Summary
CVE-2024-26154 is a newly disclosed cross-site scripting (XSS) vulnerability affecting all versions of ETIC Telecom Remote Access Server (RAS) before 4.5.0. The issue lies within the appliance site name functionality, where user-supplied input is not adequately sanitized before being displayed to administrators on various pages. Attackers can exploit this XSS vulnerability by injecting malicious scripts through the site name input field, potentially gaining unauthorized access to administrator sessions or stealing sensitive information. Upgrading to RAS version 4.5.0 or later is recommended to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.