PT-2024-5760 · Vonets · Vonets Industrial Wifi Bridge Relays+1
Wodzen
·
Published
2024-08-01
·
Updated
2024-08-20
·
CVE-2024-39815
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Vonets industrial wifi bridge relays and wifi bridge repeaters versions 3.3.23.6.9 and prior
Description
The issue is related to an improper check or handling of exceptional conditions, which enables an unauthenticated remote attacker to cause a denial of service. This can be achieved by sending a specially-crafted HTTP request to pre-authentication resources, resulting in a service crash.
Recommendations
For versions 3.3.23.6.9 and prior, update to version 3.3.23.6.9 or later as soon as possible to resolve the issue. As a temporary workaround, consider restricting access to pre-authentication resources to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vonets Industrial Wifi Bridge Relays
Vonets Wifi Bridge Repeaters