Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism that could allow an attacker to easily calculate MQTT credentials.
History

Tue, 10 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Ruijienetworks
Ruijienetworks reyee Os
CPEs cpe:2.3:o:ruijienetworks:reyee_os:*:*:*:*:*:*:*:*
Vendors & Products Ruijienetworks
Ruijienetworks reyee Os

Fri, 06 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Ruijie
Ruijie reyee Os
CPEs cpe:2.3:o:ruijie:reyee_os:*:*:*:*:*:*:*:*
Vendors & Products Ruijie
Ruijie reyee Os
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Dec 2024 18:30:00 +0000

Type Values Removed Values Added
Description Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism that could allow an attacker to easily calculate MQTT credentials.
Title Ruijie Reyee OS Use of Weak Credentials
Weaknesses CWE-1391
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2024-12-06T18:13:43.763Z

Updated: 2024-12-06T20:40:23.216Z

Reserved: 2024-11-20T23:41:59.156Z

Link: CVE-2024-45722

cve-icon Vulnrichment

Updated: 2024-12-06T19:21:39.719Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-06T19:15:12.277

Modified: 2024-12-10T19:49:53.693

Link: CVE-2024-45722

cve-icon Redhat

No data.