Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possible topics in Ruijie MQTT broker, and receive partial messages being sent to and from devices.
History

Tue, 10 Dec 2024 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Ruijienetworks
Ruijienetworks reyee Os
CPEs cpe:2.3:o:ruijienetworks:reyee_os:*:*:*:*:*:*:*:*
Vendors & Products Ruijienetworks
Ruijienetworks reyee Os

Fri, 06 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Ruijie
Ruijie reyee Os
CPEs cpe:2.3:o:ruijie:reyee_os:*:*:*:*:*:*:*:*
Vendors & Products Ruijie
Ruijie reyee Os
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Dec 2024 18:30:00 +0000

Type Values Removed Values Added
Description Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possible topics in Ruijie MQTT broker, and receive partial messages being sent to and from devices.
Title Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbols
Weaknesses CWE-155
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-12-06T18:16:07.652Z

Updated: 2024-12-06T20:40:14.508Z

Reserved: 2024-11-20T23:41:59.164Z

Link: CVE-2024-47791

cve-icon Vulnrichment

Updated: 2024-12-06T19:21:37.154Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-06T19:15:12.750

Modified: 2024-12-10T19:44:43.937

Link: CVE-2024-47791

cve-icon Redhat

No data.