Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial number if physically adjacent and sniffing the RAW WIFI signal.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-42786 Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial number if physically adjacent and sniffing the RAW WIFI signal.
Fixes

Solution

Ruijie reports that the issues have been fixed on the cloud and no action is needed by end users. However, CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as: * Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 . * Locate control system networks and remote devices behind firewalls and isolating them from business networks. * When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.


Workaround

No workaround given by the vendor.

History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00027}

epss

{'score': 0.0003}


Tue, 10 Dec 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Ruijienetworks
Ruijienetworks reyee Os
CPEs cpe:2.3:o:ruijienetworks:reyee_os:*:*:*:*:*:*:*:*
Vendors & Products Ruijienetworks
Ruijienetworks reyee Os

Fri, 06 Dec 2024 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Dec 2024 18:45:00 +0000

Type Values Removed Values Added
Description Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial number if physically adjacent and sniffing the RAW WIFI signal.
Title Ruijie Reyee OS Resource Leak
Weaknesses CWE-402
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-12-06T20:21:34.147Z

Reserved: 2024-11-20T23:41:59.193Z

Link: CVE-2024-47146

cve-icon Vulnrichment

Updated: 2024-12-06T19:19:03.559Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-06T19:15:12.603

Modified: 2024-12-10T19:45:51.023

Link: CVE-2024-47146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.