CRITICAL🇵🇱 Wersja polska

CVE-2024-34947

CVSS 9.4v3.1pub. 2024-05-20upd. 2026-04-15

Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirect attack.

🤖 AI Analysis
How it works

The ICMP redirect attack involves sending crafted ICMP 'Redirect' type packets to a vulnerable network device. The device, accepting these packets without proper verification, updates its routing table according to the instructions contained in the packets. As a result, network traffic can be redirected through a host controlled by the attacker, enabling a man-in-the-middle attack. The vulnerability (CWE-941) results from improper specification of allowed control message types.

Impact

An attacker can intercept, eavesdrop on, or modify network traffic passing through the device (man-in-the-middle attack), as well as disrupt service availability by redirecting traffic to false addresses. Combined with high confidentiality and integrity ratings, this can lead to data leakage and unauthorized modification of network communications.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references. As a temporary workaround, it is recommended to disable the acceptance of ICMP redirect packets on the device and restrict access to the device from external networks using a firewall.

Who is affected

Quanxun Huiju Network Technology (Beijing) Co., Ltd IK-Q3000 version 3.7.10 x64 Build202401261655

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References