Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf of Ruijie's cloud.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01 | Third Party Advisory US Government Resource |
Configurations
History
10 Dec 2024, 19:49
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:ruijienetworks:reyee_os:*:*:*:*:*:*:*:* | |
CWE | ||
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.9 |
First Time |
Ruijienetworks
Ruijienetworks reyee Os |
|
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01 - Third Party Advisory, US Government Resource |
06 Dec 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-06 19:15
Updated : 2024-12-10 19:49
NVD link : CVE-2024-46874
Mitre link : CVE-2024-46874
JSON object : View
Products Affected
ruijienetworks
- reyee_os
CWE
No CWE.