CVE-2024-42494: Ruijie Reyee OS Exposure of Private Personal Information to an Unauthorized Actor
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a a feature that could enable sub accounts or attackers to view and exfiltrate sensitive information from all cloud accounts registered to Ruijie's services
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42494?
CVE-2024-42494 is classified as a significant vulnerability due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2024-42494?
To mitigate CVE-2024-42494, upgrade your Ruijie Reyee OS to a version that is 2.320.x or higher.
What versions of Ruijie Reyee OS are affected by CVE-2024-42494?
CVE-2024-42494 affects Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x.
What potential impact does CVE-2024-42494 pose to users?
CVE-2024-42494 can allow sub accounts or attackers to view and exfiltrate sensitive information from registered cloud accounts.
Is there a workaround for CVE-2024-42494 while I plan for an upgrade?
Currently, there are no recommended workarounds for CVE-2024-42494 other than upgrading to a secure version of the OS.