PT-2024-9571 · Ruijie · Ruijie Reyee Os

Published

2024-12-03

·

Updated

2024-12-10

·

CVE-2024-47791

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Ruijie Reyee OS versions 2.206.x through 2.320.x
Description The issue is related to the Ruijie MQTT broker in Ruijie Reyee OS, where an attacker could subscribe to partial possible topics and receive partial messages being sent to and from devices. This is due to the lack of measures to neutralize wildcard or matching symbols. Exploitation of this issue may allow a remote attacker to gain unauthorized access to protected information.
Recommendations For Ruijie Reyee OS versions 2.206.x through 2.320.x, consider disabling the MQTT broker functionality until a patch is available to prevent potential exploitation. Restrict access to the MQTT broker to minimize the risk of unauthorized access. Avoid using wildcard or matching symbols in topic subscriptions to reduce the vulnerability to partial message interception. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Neutralization of Wildcards

Weakness Enumeration

Related Identifiers

BDU:2024-11278
CVE-2024-47791

Affected Products

Ruijie Reyee Os