CVE-2022-41607

MEDIUM

ETIC Telecom RAS <4.5.0 - Path Traversal

Title source: llm
STIX 2.1

Description

All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vulnerable to directory traversal through several different methods. This could allow an attacker to read sensitive files from the server, including SSH private keys, passwords, scripts, python objects, database files, and more.

References (1)

Core 1
Core References
Patch, Third Party Advisory, US Government Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-307-01

Scores

CVSS v3 6.2
EPSS 0.0095
EPSS Percentile 56.9%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
etictelecom/remote_access_server_firmware < 4.5.0
Published Nov 10, 2022
Tracked Since Feb 18, 2026