CVE-2024-1491
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
18/04/2024
Last modified:
28/05/2024
Description
The devices allow access to an unprotected endpoint that allows MPFS <br />
file system binary image upload without authentication. The MPFS2 file <br />
system module provides a light-weight read-only file system that can be <br />
stored in external EEPROM, external serial flash, or internal flash <br />
program memory. This file system serves as the basis for the HTTP2 web <br />
server module, but is also used by the SNMP module and is available to <br />
other applications that require basic read-only storage capabilities. <br />
This can be exploited to overwrite the flash program memory that holds <br />
the web server&#39;s main interfaces and execute arbitrary code.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



