Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf of Ruijie's cloud.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01 | Third Party Advisory US Government Resource | 
Configurations
                    History
                    10 Dec 2024, 19:49
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01 - Third Party Advisory, US Government Resource | |
| Summary | 
 | |
| First Time | Ruijienetworks Ruijienetworks reyee Os | |
| CPE | cpe:2.3:o:ruijienetworks:reyee_os:*:*:*:*:*:*:*:* | 
06 Dec 2024, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-12-06 19:15
Updated : 2024-12-10 19:49
NVD link : CVE-2024-46874
Mitre link : CVE-2024-46874
CVE.ORG link : CVE-2024-46874
JSON object : View
Products Affected
                ruijienetworks
- reyee_os
CWE
                
                    
                        
                        CWE-280
                        
            Improper Handling of Insufficient Permissions or Privileges
