CVE-2024-26155

All versions of ETIC Telecom Remote Access Server (RAS) prior to 4.5.0 
expose clear text credentials in the web portal. An attacker can access 
the ETIC RAS web portal and view the HTML code, which is configured to 
be hidden, thus allowing a connection to the ETIC RAS ssh server, which 
could enable an attacker to perform actions on the device.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
icscertCNA
6.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
CISA-ADPADP
---
---