CVE-2022-3703 HIGH

CVE-2022-3703: ETIC Telecom Remote Access Server Insufficient Verification of Data Authenticity

Vendor Etic Telecom
Product Remote Access Server (RAS)
Weakness CWE-345
Published November 10, 2022
Last update April 16, 2025

CVSS base score

7.6/10
Attack vector Adjacent
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s web portal is vulnerable to accepting malicious firmware packages that could provide a backdoor to an attacker and provide privilege escalation to the device.

Key dates

02Disclosure timeline

November 10, 2022 CVE published
April 16, 2025 Record updated