Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49462 | Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle. |
Solution
CIRCUTOR TCP2RS+ device firmware version 1.3.b (2017), presents 2 security vulnerabilities exploitable mainly in public communication networks, especially in networks not adequately protected. CIRCUTOR strongly recommends replacing the TCP2RS+ device with the current Line-TCPRS1, both in private and public network environments.
Workaround
No workaround given by the vendor.
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Mon, 07 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Circutor
Circutor tcp2rs\+ Circutor tcp2rs\+ Firmware |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:h:circutor:tcp2rs\+:-:*:*:*:*:*:*:* cpe:2.3:h:circutor:tcp2rs\+_firmware:1.3b:*:*:*:*:*:*:* |
|
| Vendors & Products |
Circutor
Circutor tcp2rs\+ Circutor tcp2rs\+ Firmware |
Wed, 18 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Sep 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle. | |
| Title | Uncontrolled Resource Consumption vulnerability on CIRCUTOR TCP2RS+ | |
| Weaknesses | CWE-400 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-09-18T14:42:50.191Z
Reserved: 2024-09-16T10:20:33.376Z
Link: CVE-2024-8892
Updated: 2024-09-18T14:42:46.479Z
Status : Analyzed
Published: 2024-09-18T13:15:03.907
Modified: 2024-10-07T17:10:26.673
Link: CVE-2024-8892
No data.
OpenCVE Enrichment
No data.
EUVD