CVE-2024-46874: Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privileges
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf of Ruijie's cloud.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46874?
CVE-2024-46874 has been classified as a high severity vulnerability due to the potential for unauthorized command execution on other devices.
How do I fix CVE-2024-46874?
To mitigate CVE-2024-46874, upgrade Ruijie Reyee OS to version 2.320.x or later.
Who is affected by CVE-2024-46874?
CVE-2024-46874 affects Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x.
What type of attacks are possible with CVE-2024-46874?
Attackers can exploit CVE-2024-46874 to issue commands to devices on behalf of Ruijie’s cloud if they possess valid device credentials.
What is the impact of CVE-2024-46874?
The impact of CVE-2024-46874 includes the potential for device manipulation and unauthorized access to sensitive information.