CVE-2024-1491

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
18/04/2024
Last modified:
28/05/2024

Description

The devices allow access to an unprotected endpoint that allows MPFS <br /> file system binary image upload without authentication. The MPFS2 file <br /> system module provides a light-weight read-only file system that can be <br /> stored in external EEPROM, external serial flash, or internal flash <br /> program memory. This file system serves as the basis for the HTTP2 web <br /> server module, but is also used by the SNMP module and is available to <br /> other applications that require basic read-only storage capabilities. <br /> This can be exploited to overwrite the flash program memory that holds <br /> the web server&amp;#39;s main interfaces and execute arbitrary code.

References to Advisories, Solutions, and Tools