Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5ggp-fmj8-fxvf

Опубликовано: 06 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 8.1

Описание

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf of Ruijie's cloud.

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf of Ruijie's cloud.

EPSS

Процентиль: 29%
0.00108
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-280

Связанные уязвимости

CVSS3: 8.1
nvd
около 1 года назад

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow MQTT clients connecting with device credentials to send messages to some topics. Attackers with device credentials could issue commands to other devices on behalf of Ruijie's cloud.

CVSS3: 8.1
fstec
около 1 года назад

Уязвимость брокера MQTT операционной системы Ruijie Reyee OS, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 29%
0.00108
Низкий

9.2 Critical

CVSS4

8.1 High

CVSS3

Дефекты

CWE-280