PT-2024-20204 · Alpine · Alpine Halo9

Le Tran Hai Tung

·

Published

2024-06-21

·

Updated

2025-08-12

·

CVE-2024-23962

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Alpine Halo9 devices (affected versions not specified)
Description This issue allows remote attackers to disclose sensitive information on affected installations. Authentication is not required to exploit this issue. The specific flaw exists within the DLT interface, which listens on TCP port 3490 by default. The problem results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this in conjunction with other issues to execute arbitrary code in the context of the device.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

LPE

Missing Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-23962
ZDI-24-847

Affected Products

Alpine Halo9