Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle.
History

Wed, 18 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 13:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle.
Title Uncontrolled Resource Consumption vulnerability on CIRCUTOR TCP2RS+
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2024-09-18T12:54:04.077Z

Updated: 2024-09-18T14:42:50.191Z

Reserved: 2024-09-16T10:20:33.376Z

Link: CVE-2024-8892

cve-icon Vulnrichment

Updated: 2024-09-18T14:42:46.479Z

cve-icon NVD

Status : Received

Published: 2024-09-18T13:15:03.907

Modified: 2024-09-18T13:15:03.907

Link: CVE-2024-8892

cve-icon Redhat

No data.