CVE-2024-48874: Ruijie Reyee OS Server-Side Request Forgery
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud infrastructure via AWS cloud metadata services.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48874?
CVE-2024-48874 has a high severity rating due to its potential to allow attackers to access internal services.
How do I fix CVE-2024-48874?
To fix CVE-2024-48874, upgrade Ruijie Reyee OS to version 2.320.x or later.
Which versions of Ruijie Reyee OS are affected by CVE-2024-48874?
CVE-2024-48874 affects Ruijie Reyee OS versions from 2.206.x up to but not including 2.320.x.
What kind of attacks can be performed using CVE-2024-48874?
CVE-2024-48874 allows attackers to force proxy servers to perform arbitrary requests, potentially accessing sensitive internal services.
Who is impacted by CVE-2024-48874?
Organizations using Ruijie Reyee OS versions 2.206.x to 2.319.x are impacted by CVE-2024-48874.