An issue was found on the Ruijie EG-2000 series gateway. There is a buffer overflow in client.so. Consequently, an attacker can use login.php to login to any account, without providing its password. This affects EG-2000SE EG_RGOS 11.1(1)B1.
References
Link Providers
https://0x.mk/?p=239 cve-icon cve-icon cve-icon
History

Mon, 12 Aug 2024 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-07-16T00:00:00

Updated: 2024-08-12T17:53:14.425Z

Reserved: 2019-09-20T00:00:00

Link: CVE-2019-16641

cve-icon Vulnrichment

Updated: 2024-08-05T01:17:41.043Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-16T17:15:10.600

Modified: 2024-11-21T04:30:52.080

Link: CVE-2019-16641

cve-icon Redhat

No data.