Metrics
Affected Vendors & Products
| Link | Providers | 
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-847/ |     | 
Tue, 12 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Alpsalpine Alpsalpine ilx-f509 Alpsalpine ilx-f509 Firmware | |
| CPEs | cpe:2.3:o:alpine-usa:ilx-f509_firmware:*:*:*:*:*:*:*:* | cpe:2.3:h:alpsalpine:ilx-f509:-:*:*:*:*:*:*:* cpe:2.3:o:alpsalpine:ilx-f509_firmware:*:*:*:*:*:*:*:* | 
| Vendors & Products | Alpine-usa Alpine-usa ilx-f509 Alpine-usa ilx-f509 Firmware | Alpsalpine Alpsalpine ilx-f509 Alpsalpine ilx-f509 Firmware | 
Mon, 30 Jun 2025 17:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 | cvssV3_1 
 | 
Tue, 24 Jun 2025 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Alpine-usa Alpine-usa ilx-f509 Alpine-usa ilx-f509 Firmware | |
| CPEs | cpe:2.3:h:alpine-usa:ilx-f509:-:*:*:*:*:*:*:* cpe:2.3:o:alpine-usa:ilx-f509_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products | Alpine-usa Alpine-usa ilx-f509 Alpine-usa ilx-f509 Firmware | 
Wed, 19 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-200 | |
| Metrics | cvssV3_1 
 | 
Tue, 18 Feb 2025 19:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics | cvssV3_1 
 | 
Fri, 31 Jan 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-862 | |
| Metrics | cvssV3_1 
 
 | 
Fri, 31 Jan 2025 00:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Alpine Halo9 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the DLT interface, which listens on TCP port 3490 by default. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device. | |
| Title | Alpine Halo9 Missing Authentication | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: icscert
Published: 2025-01-30T23:53:33.224Z
Updated: 2025-07-01T13:43:07.238Z
Reserved: 2024-01-25T00:14:40.299Z
Link: CVE-2024-23962
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-01-31T17:00:28.888Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-01-31T00:15:09.367
Modified: 2025-08-12T18:13:55.387
Link: CVE-2024-23962
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow