02 Records
FEED: ACQUIRING
01 RecordSTATE: PUBLISHED
02 Description
CNA: icscertETIC Telecom Remote Access Server Unrestricted Upload of File with Dangerous Type
03 Exploitation and scoring
SRC: CISA, FIRST, NVD, RED HAT- Exploitation
- Not assessed. CISA has not published an exploitation assessment for this record, and it is not in the KEV catalog. That is an absence of assessment, not a finding of no risk.
- SSVC decision
- Not assessed by CISA
- EPSS probability
- 0.52% probability of exploitation activity in the next 30 days.
- EPSS percentile
- Ranks above 41.9% of scored records. A rank, not a probability.
- NVD base score
- 10.0 (CVSS v3.x), scored by the NVD independently of the CNA.
- NVD CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- NVD analysis status
- Modified. NVD last modified this record on 2026-06-17.
- Red Hat severity
- No Red Hat rating. Red Hat rates the CVEs that affect its products.
Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.
SCHEMA: 5.1
- Published
- 2022-11-10 21:31Z3 YR AGO
- Last updated
- 2024-09-16 23:40Z1 YR AGO
- Reserved
- 2022-09-29
- Assigning CNA
- icscert
- Record state
- PUBLISHED
- Severity
- Medium (CVSS 5.9)
- CNA CVSS vector
- CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
- Weaknesses
- CWE-434Unrestricted Upload of File with Dangerous TypeBase
- Data version
- 5.1
- Document digest
- 209b411f2f4d76f9c440ae9cc60c95241b26aba1ab193c046433e9cb4ae11caa
05 Affected products
PAIRS: 1VendorProductVersionsPlatforms
SRC: CNA
ETIC Telecom recommends updating the firmware of the affected devices to the following versions:
* ETIC Telecom RAS: version 4.7.0 or later https://www.etictelecom.com/en/softwares-download/
For the installed devices, ETIC Telecom recommends:
* For all firmware versions 4.7.0 and above, only valid configuration files can be uploaded to the device. For versions prior to 4.7.0, to reduce the attack surface, we advise the user to verify in the router configuration that: (1) The administration web page is accessible only through the LAN side over HTTPS, and (2) The administration web page is protected with authentication.