Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49459 | Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle. |
Solution
CIRCUTOR TCP2RS+ device firmware version 1.3.b (2017), presents 2 security vulnerabilities exploitable mainly in public communication networks, especially in networks not adequately protected. CIRCUTOR strongly recommends replacing the TCP2RS+ device with the current Line-TCPRS1, both in private and public network environments.
Workaround
No workaround given by the vendor.
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 07 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Circutor tcp2rs\+
Circutor tcp2rs\+ Firmware |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:h:circutor:tcp2rs\+:-:*:*:*:*:*:*:* cpe:2.3:h:circutor:tcp2rs\+_firmware:1.3b:*:*:*:*:*:*:* |
|
| Vendors & Products |
Circutor tcp2rs\+
Circutor tcp2rs\+ Firmware |
Wed, 18 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Circutor
Circutor circutor Tcp2rs Plus |
|
| CPEs | cpe:2.3:a:circutor:circutor_tcp2rs_plus:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Circutor
Circutor circutor Tcp2rs Plus |
|
| Metrics |
ssvc
|
Wed, 18 Sep 2024 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle. | |
| Title | Improper Input Validation vulnerability on CIRCUTOR TCP2RS+ | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-18T13:09:03.920Z
Reserved: 2024-09-16T10:20:30.893Z
Link: CVE-2024-8889
Updated: 2024-09-18T13:07:51.938Z
Status : Analyzed
Published: 2024-09-18T12:15:03.710
Modified: 2024-10-07T17:09:27.603
Link: CVE-2024-8889
No data.
OpenCVE Enrichment
No data.
EUVD