CVE-2022-3703
Last modified
CVE-2022-3703 is a critical-severity vulnerability rated 10/10 on the CVSS scale. All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Etictelecom | Remote Access Server Firmware | <= 4.5.0 |
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-01Patch, Third Party Advisory, US Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-01Patch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3703?
How severe is CVE-2022-3703?
How do I fix CVE-2022-3703?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-37023Apache Geode versions prior to 1.15.0 are vulnerable to a de…6.5
- CVE-2022-37024Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, …8.8
- CVE-2022-37025An improper privilege management vulnerability in McAfee Sec…7.8
- CVE-2022-37026In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25…9.8
- CVE-2022-37027Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user t…7.2
- CVE-2022-37028ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS)…5.4
- CVE-2022-37030Weak permissions on the configuration file in the PAM module…7.8
- CVE-2022-37032An out-of-bounds read in the BGP daemon of FRRouting FRR bef…9.1
- CVE-2022-37033In dotCMS 5.x-22.06, TempFileAPI allows a user to create a t…6.5
- CVE-2022-37034In dotCMS 5.x-22.06, it is possible to call the TempResource…5.3
- CVE-2022-37035An issue was discovered in bgpd in FRRouting (FRR) 8.3. In b…8.1
- CVE-2022-3704A vulnerability classified as problematic has been found in …5.4
Are you affected by CVE-2022-3703?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
