CVE-2024-26154

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 
are vulnerable to reflected cross site scripting in the appliance site 
name. The ETIC RAS web server saves the site name and then presents it 
to the administrators in a few different pages.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
icscertCNA
4.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CISA-ADPADP
---
---