ETIC Telecom Remote Access Server
cpe:2.3:a:etictelecom:remote_access_server:*:*:*:*:*:*:*, +1 more
- < 4.5.0
- < 4.9.19
A vulnerability exists in all versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0, where cleartext credentials are exposed in the web portal. This allows an attacker to access the ETIC RAS web portal, view hidden HTML code, and connect to the ETIC RAS SSH server, potentially enabling actions on the device.
Exploitation of this vulnerability could lead to unauthorized access to the ETIC RAS SSH server, allowing an attacker to perform actions on the affected device.
Users are advised to update to ETIC Telecom Remote Access Server version 4.5.0 or later. For versions prior to 4.5.0, ETIC Telecom recommends ensuring that the administration web page is accessible only through the LAN side over HTTPS and is protected with authentication.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.