CVE-2022-41607
Summary
| CVE | CVE-2022-41607 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-10 22:15:00 UTC |
| Updated | 2023-12-28 19:15:00 UTC |
| Description | All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vulnerable to directory traversal through several different methods. This could allow an attacker to read sensitive files from the server, including SSH private keys, passwords, scripts, python objects, database files, and more. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Etictelecom | Ras-c-100-lw | - | All | All | All |
| Hardware | Etictelecom | Ras-e-100 | - | All | All | All |
| Hardware | Etictelecom | Ras-e-220 | - | All | All | All |
| Hardware | Etictelecom | Ras-e-400 | - | All | All | All |
| Hardware | Etictelecom | Ras-ec-220-lw | - | All | All | All |
| Hardware | Etictelecom | Ras-ec-400-lw | - | All | All | All |
| Hardware | Etictelecom | Ras-ec-480-lw | - | All | All | All |
| Hardware | Etictelecom | Ras-ecw-220-lw | - | All | All | All |
| Hardware | Etictelecom | Ras-ecw-400-lw | - | All | All | All |
| Hardware | Etictelecom | Ras-ew-100 | - | All | All | All |
| Hardware | Etictelecom | Ras-ew-220 | - | All | All | All |
| Hardware | Etictelecom | Ras-ew-400 | - | All | All | All |
| Application | Etictelecom | Remote Access Server | All | All | All | All |
| Operating System | Etictelecom | Remote Access Server Firmware | All | All | All | All |
| Hardware | Etictelecom | Rfm-e | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ETIC Telecom Remote Access Server (RAS) | CISA | MISC | www.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.