An improper input validation vulnerability was discovered...
High severity
Unreviewed
Published
Feb 24, 2025
to the GitHub Advisory Database
•
Updated Feb 24, 2025
Description
Published by the National Vulnerability Database
Feb 24, 2025
Published to the GitHub Advisory Database
Feb 24, 2025
Last updated
Feb 24, 2025
An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card. This could result in an authenticated high privileged user having the ability to execute arbitrary commands. The vulnerability has been resolved in the version 3.0.4.
Note - Network-M2 has been declared end-of-life in early 2024 and Network-M3 has been released as a fit-and-functional replacement.
References