CRITICAL🇵🇱 Wersja polska

CVE-2024-47547

CVSS 9.3v4.0pub. 2024-12-06upd. 2024-12-10

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a weak mechanism for its users to change their passwords which leaves authentication vulnerable to brute force attacks.

🤖 AI Analysis
How it works

The password change mechanism implemented in Ruijie Reyee OS is too weak to effectively protect against automated password guessing (CWE-640 — Weak Password Recovery Mechanism for Forgotten Password). An attacker remotely, without the need to have privileges or engage the victim, can conduct a brute force attack on the authentication process, repeatedly trying different password combinations without effective blocking or limiting of attempts.

Impact

An attacker can take over a user account by guessing the password, leading to unauthorized access to the system and potential compromise of confidentiality and integrity of data managed by the device.

Mitigation & patch

Ruijie Reyee OS should be updated to version 2.320.x or later. Detailed information about available patches can be found in the ICS-CERT advisory ICSA-24-338-01 available at: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01

Who is affected

Ruijie Reyee OS in versions from 2.206.x to (excluding) 2.320.x

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Ruijienetworks Reyee Os

    OS
    Ruijienetworks
    2.206.0 – 2.320.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-53881CRITICAL9.2PL ✓same product

ReyeeOS: RCE przez niezaszyfrowaną komunikację CWMP (MitM)

CVE-2024-52324CRITICAL9.2PL ✓same product

RCE poprzez niebezpieczną funkcję w Ruijie Reyee OS — wykonanie dowolnych poleceń OS

CVE-2024-48874CRITICAL9.3PL ✓same product

SSRF w Ruijie Reyee OS — dostęp do wewnętrznej infrastruktury chmurowej

CVE-2024-46874CRITICAL9.2PL ✓same product

Ruijie Reyee OS — nieautoryzowane polecenia do urządzeń przez MQTT

CVE-2025-56077HIGH8.8same product

OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary co...