CVE Vulnerabilities

CVE-2024-47146

Transmission of Private Resources into a New Sphere ('Resource Leak')

Published: Dec 06, 2024 | Modified: Dec 10, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to obtain the devices serial number if physically adjacent and sniffing the RAW WIFI signal.

Weakness

The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.

Affected Software

NameVendorStart VersionEnd Version
Reyee_osRuijienetworks2.206.0 (including)2.320.0 (excluding)

References