CVE-2024-25008
EUVD-2024-2237016.08.2024, 10:15
Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated privileges for example a valid OAM user having the system administrator role to exploit the vulnerability.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| ericsson | controller_6610 | 𝑥 < 24.q2 | ADP |
| ericsson | ran_compute | 𝑥 < 24.q2 | ADP |
Common Weakness Enumeration