Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39277 | The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass authentication, and execute remote code. |
Solution
No solution given by the vendor.
Workaround
Optigo Networks recommends users always use a unique management VLAN for the port on the ONS-S8 that is used to connect to OneView. Optigo Networks also recommends users implement at least one of the following additional mitigations: * Use a dedicated NIC on the BMS computer and exclusively this computer for connecting to OneView to manage your OT network configuration. * Set up a router firewall with a white list for the devices permitted to access OneView. * Connect to OneView via secure VPN.
Fri, 04 Oct 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Optigo
Optigo ons-s8 Firmware |
|
| CPEs | cpe:2.3:o:optigo:ons-s8_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Optigo
Optigo ons-s8 Firmware |
|
| Metrics |
ssvc
|
Thu, 03 Oct 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass authentication, and execute remote code. | |
| Title | Optigo Networks ONS-S8 Spectra Aggregation Switch PHP Remote File Inclusion | |
| Weaknesses | CWE-98 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-10-04T14:25:26.785Z
Reserved: 2024-09-16T16:21:37.465Z
Link: CVE-2024-41925
Updated: 2024-10-04T14:25:22.682Z
Status : Awaiting Analysis
Published: 2024-10-03T23:15:02.970
Modified: 2024-10-04T13:50:43.727
Link: CVE-2024-41925
No data.
OpenCVE Enrichment
No data.
EUVD