CVE Vulnerabilities

CVE-2024-47146

Transmission of Private Resources into a New Sphere ('Resource Leak')

Published: Dec 06, 2024 | Modified: Dec 10, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial number if physically adjacent and sniffing the RAW WIFI signal.

Weakness

The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.

Affected Software

Name Vendor Start Version End Version
Reyee_os Ruijienetworks 2.206.0 (including) 2.320.0 (excluding)

References