CVE-2024-28754: High severity RaspAP RaspAP vulnerability
Published Mar 8, 2024
·Updated
RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to cause a persistent denial of service (bricking) via a crafted request.
Affected Software
2 affected componentsFixes available
composer/billz/raspap-webgui<3.1.0
3.1.0
RaspAP RaspAP<=3.0.9
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/billz/raspap-webguito a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Mar 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 9, 2024
Data Sourced
via NVD·12:15 AM
DescriptionSeverity
Advisory Published
via GitHub·12:31 AM
Apr 5, 58713
Event
via FIRST·07:43 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-28754?
CVE-2024-28754 is classified as a high severity vulnerability due to its potential to cause a persistent denial of service.
2
How do I fix CVE-2024-28754?
To fix CVE-2024-28754, you should upgrade RaspAP to version 3.1.0 or later.
3
Who is affected by CVE-2024-28754?
CVE-2024-28754 affects all versions of RaspAP prior to 3.1.0.
4
What type of attack does CVE-2024-28754 describe?
CVE-2024-28754 describes a remote attack that can lead to a persistent denial of service.
5
What software component does CVE-2024-28754 pertain to?
CVE-2024-28754 pertains to the RaspAP web GUI software.