The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass authentication, and execute remote code.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Optigo
Optigo ons-s8 Firmware |
|
| CPEs | cpe:2.3:o:optigo:ons-s8_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Optigo
Optigo ons-s8 Firmware |
|
| Metrics |
ssvc
|
Thu, 03 Oct 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass authentication, and execute remote code. | |
| Title | Optigo Networks ONS-S8 Spectra Aggregation Switch PHP Remote File Inclusion | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-10-04T14:25:26.785Z
Reserved: 2024-09-16T16:21:37.465Z
Link: CVE-2024-41925
Updated: 2024-10-04T14:25:22.682Z
Status : Awaiting Analysis
Published: 2024-10-03T23:15:02.970
Modified: 2024-10-04T13:50:43.727
Link: CVE-2024-41925
No data.