Search

Find a vulnerability

Search criteria

    2 vulnerabilities found for tswos by teltonika-networks

    CVE-2024-8256 (GCVE-0-2024-8256)

    Vulnerability from nvd – Published: 2024-12-10 08:56 – Updated: 2024-12-10 15:35
    VLAI
    Title
    Incorrect Permission Assignment in RutOS based routers and TSWOS based managed switches
    Summary
    In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-10 15:32 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    References
    Impacted products
    Vendor Product Version
    Teltonika Networks RUTOS Affected: 7.0 , < 7.8 (custom)
    Create a notification for this product.
    Teltonika Networks TSWOS Affected: 1.0 , < 1.3 (custom)
    Create a notification for this product.
    teltonika-networks rutos_devices Affected: 7.0 , < 7.8 (custom)
        cpe:2.3:a:teltonika-networks:rutos_devices:7.0:*:*:*:*:*:*:*
    Create a notification for this product.
    teltonika-networks tswos Affected: 1.0 , < 1.3 (custom)
        cpe:2.3:a:teltonika-networks:tswos:1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:teltonika-networks:rutos_devices:7.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "rutos_devices",
                "vendor": "teltonika-networks",
                "versions": [
                  {
                    "lessThan": "7.8",
                    "status": "affected",
                    "version": "7.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:teltonika-networks:tswos:1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "tswos",
                "vendor": "teltonika-networks",
                "versions": [
                  {
                    "lessThan": "1.3",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8256",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-10T15:32:26.176120Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-10T15:35:59.297Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "RUTOS",
              "vendor": "Teltonika Networks",
              "versions": [
                {
                  "lessThan": "7.8",
                  "status": "affected",
                  "version": "7.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TSWOS",
              "vendor": "Teltonika Networks",
              "versions": [
                {
                  "lessThan": "1.3",
                  "status": "affected",
                  "version": "1.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API."
                }
              ],
              "value": "In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "ADJACENT",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-10T08:56:55.195Z",
            "orgId": "001d69cf-3fc9-4203-93fb-9865b54e05b2",
            "shortName": "tlt_net"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.deepcove.support/teltonika-responsible-disclosure-proactive-testing-report/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Incorrect Permission Assignment in RutOS based routers and TSWOS based managed switches",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "001d69cf-3fc9-4203-93fb-9865b54e05b2",
        "assignerShortName": "tlt_net",
        "cveId": "CVE-2024-8256",
        "datePublished": "2024-12-10T08:56:55.195Z",
        "dateReserved": "2024-08-28T05:26:25.399Z",
        "dateUpdated": "2024-12-10T15:35:59.297Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-8256 (GCVE-0-2024-8256)

    Vulnerability from cvelistv5 – Published: 2024-12-10 08:56 – Updated: 2024-12-10 15:35
    VLAI
    Title
    Incorrect Permission Assignment in RutOS based routers and TSWOS based managed switches
    Summary
    In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-12-10 15:32 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    References
    Impacted products
    Vendor Product Version
    Teltonika Networks RUTOS Affected: 7.0 , < 7.8 (custom)
    Create a notification for this product.
    Teltonika Networks TSWOS Affected: 1.0 , < 1.3 (custom)
    Create a notification for this product.
    teltonika-networks rutos_devices Affected: 7.0 , < 7.8 (custom)
        cpe:2.3:a:teltonika-networks:rutos_devices:7.0:*:*:*:*:*:*:*
    Create a notification for this product.
    teltonika-networks tswos Affected: 1.0 , < 1.3 (custom)
        cpe:2.3:a:teltonika-networks:tswos:1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:teltonika-networks:rutos_devices:7.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "rutos_devices",
                "vendor": "teltonika-networks",
                "versions": [
                  {
                    "lessThan": "7.8",
                    "status": "affected",
                    "version": "7.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:teltonika-networks:tswos:1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "tswos",
                "vendor": "teltonika-networks",
                "versions": [
                  {
                    "lessThan": "1.3",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-8256",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-12-10T15:32:26.176120Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-10T15:35:59.297Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "RUTOS",
              "vendor": "Teltonika Networks",
              "versions": [
                {
                  "lessThan": "7.8",
                  "status": "affected",
                  "version": "7.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "TSWOS",
              "vendor": "Teltonika Networks",
              "versions": [
                {
                  "lessThan": "1.3",
                  "status": "affected",
                  "version": "1.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API."
                }
              ],
              "value": "In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling a vulnerability exists which allows a lower privileged user with default permissions to access critical device resources via the API."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "ADJACENT",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732 Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-12-10T08:56:55.195Z",
            "orgId": "001d69cf-3fc9-4203-93fb-9865b54e05b2",
            "shortName": "tlt_net"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.deepcove.support/teltonika-responsible-disclosure-proactive-testing-report/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Incorrect Permission Assignment in RutOS based routers and TSWOS based managed switches",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "001d69cf-3fc9-4203-93fb-9865b54e05b2",
        "assignerShortName": "tlt_net",
        "cveId": "CVE-2024-8256",
        "datePublished": "2024-12-10T08:56:55.195Z",
        "dateReserved": "2024-08-28T05:26:25.399Z",
        "dateUpdated": "2024-12-10T15:35:59.297Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }