All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting in the appliance site name. The ETIC RAS web server saves the site name and then presents it to the administrators in a few different pages.
History

Wed, 30 Jul 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Etictelecom
Etictelecom remote Access Server Firmware
CPEs cpe:2.3:o:etictelecom:remote_access_server_firmware:*:*:*:*:*:*:*:*
Vendors & Products Etictelecom
Etictelecom remote Access Server Firmware

Tue, 21 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jan 2025 16:30:00 +0000

Type Values Removed Values Added
Description All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 are vulnerable to reflected cross site scripting in the appliance site name. The ETIC RAS web server saves the site name and then presents it to the administrators in a few different pages.
Title ETIC Telecom Remote Access Server (RAS) Cross-site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2025-01-17T16:17:10.899Z

Updated: 2025-01-21T14:56:13.407Z

Reserved: 2024-02-14T22:03:32.380Z

Link: CVE-2024-26154

cve-icon Vulnrichment

Updated: 2025-01-21T14:55:58.698Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-17T17:15:11.147

Modified: 2025-07-30T17:13:00.863

Link: CVE-2024-26154

cve-icon Redhat

No data.