CRITICAL🇵🇱 Wersja polska

CVE-2024-39815

CVSS 9.4v4.0pub. 2024-08-12upd. 2024-08-20

Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to cause a denial of service. A specially-crafted HTTP request to pre-authentication resources can crash the service.

🤖 AI Analysis
How it works

The vulnerability results from improper handling of exceptional conditions (CWE-703) in the pre-authentication layer of the device's HTTP service. An attacker sends a specially crafted HTTP request directed at resources available before authentication, which causes the service to crash. Since the exploit does not require any credentials, network access to the device is sufficient.

Impact

An attacker can remotely and without authentication cause a service failure (crash) on the device, resulting in network availability disruption. In industrial environments, this may mean complete disconnection of network communication handled by the bridge/repeater device.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Additionally, it is recommended to restrict network access to the Vonets device management interface only to trusted hosts and isolate industrial devices in dedicated network segments (VLAN, firewall).

Who is affected

Vonets VAR1200-H, VAR1200-L, and VAR600-H (firmware) — software versions 3.3.23.6.9 and earlier

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Vonets Vap11ac

    HW
    Vonets
    all versions
  • Vonets Vap11ac Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Vap11g

    HW
    Vonets
    all versions
  • Vonets Vap11g 300

    HW
    Vonets
    all versions
  • Vonets Vap11g 300 Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Vap11g 500

    HW
    Vonets
    all versions
  • Vonets Vap11g 500 Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Vap11g 500s

    HW
    Vonets
    all versions
  • Vonets Vap11g 500s Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Vap11g Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Vap11n 300

    HW
    Vonets
    all versions
  • Vonets Vap11n 300 Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Vap11s

    HW
    Vonets
    all versions
  • Vonets Vap11s 5g

    HW
    Vonets
    all versions
  • Vonets Vap11s 5g Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Vap11s Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Var11n 300

    HW
    Vonets
    all versions
  • Vonets Var11n 300 Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Var1200 H

    HW
    Vonets
    all versions
  • Vonets Var1200 H Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Var1200 L

    HW
    Vonets
    all versions
  • Vonets Var1200 L Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Var600 H

    HW
    Vonets
    all versions
  • Vonets Var600 H Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Vbg1200

    HW
    Vonets
    all versions
  • Vonets Vbg1200 Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
  • Vonets Vga 1000

    HW
    Vonets
    all versions
  • Vonets Vga 1000 Firmware

    OS
    Vonets
    ≤ 3.3.23.6.9
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2024-39791CRITICAL10.0PL ✓same product

Stack-based buffer overflow RCE w urządzeniach Vonets WiFi Bridge

CVE-2024-37023CRITICAL9.4PL ✓same product

Command Injection w urządzeniach Vonets WiFi Bridge — zdalne wykonanie komend

CVE-2024-46329HIGH8.0same product

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the SystemComman...

CVE-2024-46328HIGH8.0same product

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain hardcoded credentials for several different privileged...

CVE-2024-46330HIGH7.4same product

VONETS VAP11G-300 v3.3.23.6.9 was discovered to contain a command injection vulnerability via the iptablesWebs...