PT-2024-9571 · Ruijie · Ruijie Reyee Os
Published
2024-12-03
·
Updated
2024-12-10
·
CVE-2024-47791
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Ruijie Reyee OS versions 2.206.x through 2.320.x
Description
The issue is related to the Ruijie MQTT broker in Ruijie Reyee OS, where an attacker could subscribe to partial possible topics and receive partial messages being sent to and from devices. This is due to the lack of measures to neutralize wildcard or matching symbols. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information.
Recommendations
For Ruijie Reyee OS versions 2.206.x through 2.320.x, consider disabling the MQTT broker functionality until a patch is available to prevent potential exploitation. Restrict access to the MQTT broker to minimize the risk of unauthorized access. Avoid using wildcard or matching symbols in topic subscriptions to reduce the vulnerability to partial message interception. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Neutralization of Wildcards
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ruijie Reyee Os