TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication. This file system serves as the basis for the HTTP2 web server module but is also used by the SNMP module and is available to other applications that require basic read-only storage capabilities. This can be exploited to overwrite the flash program memory that holds the web server's main interfaces and execute arbitrary code.
History

Thu, 03 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Tem
Tem opera Plus Fm Family Transmitter
CPEs cpe:2.3:a:tem:opera_plus_fm_family_transmitter:*:*:*:*:*:*:*:*
Vendors & Products Tem
Tem opera Plus Fm Family Transmitter
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Oct 2024 17:45:00 +0000

Type Values Removed Values Added
Description TEM Opera Plus FM Family Transmitter allows access to an unprotected endpoint that allows MPFS File System binary image upload without authentication. This file system serves as the basis for the HTTP2 web server module but is also used by the SNMP module and is available to other applications that require basic read-only storage capabilities. This can be exploited to overwrite the flash program memory that holds the web server's main interfaces and execute arbitrary code.
Title Missing Authentication for Critical Function vulnerability in TEM Opera Plus FM Family Transmitter
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-10-03T17:40:07.153Z

Updated: 2024-10-03T18:48:36.617Z

Reserved: 2024-07-25T16:53:53.053Z

Link: CVE-2024-41988

cve-icon Vulnrichment

Updated: 2024-10-03T18:48:31.761Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-10-03T18:15:05.030

Modified: 2024-10-04T13:50:43.727

Link: CVE-2024-41988

cve-icon Redhat

No data.