Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle.
History

Mon, 07 Oct 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Circutor tcp2rs\+
Circutor tcp2rs\+ Firmware
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:h:circutor:tcp2rs\+:-:*:*:*:*:*:*:*
cpe:2.3:h:circutor:tcp2rs\+_firmware:1.3b:*:*:*:*:*:*:*
Vendors & Products Circutor tcp2rs\+
Circutor tcp2rs\+ Firmware

Wed, 18 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Circutor
Circutor circutor Tcp2rs Plus
CPEs cpe:2.3:a:circutor:circutor_tcp2rs_plus:*:*:*:*:*:*:*:*
Vendors & Products Circutor
Circutor circutor Tcp2rs Plus
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 12:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle.
Title Improper Input Validation vulnerability on CIRCUTOR TCP2RS+
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2024-09-18T12:00:11.071Z

Updated: 2024-09-18T13:09:03.920Z

Reserved: 2024-09-16T10:20:30.893Z

Link: CVE-2024-8889

cve-icon Vulnrichment

Updated: 2024-09-18T13:07:51.938Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-18T12:15:03.710

Modified: 2024-10-07T17:09:27.603

Link: CVE-2024-8889

cve-icon Redhat

No data.