CVE-2024-52285: Medium severity sipass integrated ac5102 vulnerability
A vulnerability has been identified in SiPass integrated AC5102 (ACC-G2) (All versions < V6.4.8), SiPass integrated ACC-AP (All versions < V6.4.8). Affected devices expose several MQTT URLs without authentication. This could allow an unauthenticated remote attacker to access sensitive data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52285?
CVE-2024-52285 is considered a high-severity vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2024-52285?
To fix CVE-2024-52285, upgrade your SiPass integrated AC5102 (ACC-G2) and ACC-AP devices to version 6.4.8 or later.
What are the affected versions in CVE-2024-52285?
CVE-2024-52285 affects all versions of SiPass integrated AC5102 (ACC-G2) and ACC-AP prior to version 6.4.8.
What type of attack is possible with CVE-2024-52285?
CVE-2024-52285 allows unauthenticated remote attackers to access sensitive data via exposed MQTT URLs.
Is authentication required to exploit CVE-2024-52285?
No, CVE-2024-52285 can be exploited without any authentication.