CRITICAL🇵🇱 Wersja polska

CVE-2024-48874

CVSS 9.3v4.0pub. 2024-12-06upd. 2024-12-10

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud infrastructure via AWS cloud metadata services.

🤖 AI Analysis
How it works

An attacker, without any authentication, can submit a crafted request to Ruijie proxy servers, forcing them to execute HTTP requests to any network resources chosen by the attacker. This mechanism (SSRF) allows bypassing network security and reaching internal services unavailable directly from the Internet. In particular, an attacker can access AWS instance metadata (AWS cloud metadata services), which may lead to obtaining sensitive configuration and authentication data of Ruijie's cloud infrastructure.

Impact

An attacker may gain access to internal Ruijie services and data from AWS cloud infrastructure, including potentially sensitive authentication and configuration data. This could lead to further compromise of the manufacturer's cloud environment and devices managed by this infrastructure.

Mitigation & patch

Ruijie Reyee OS should be updated to version 2.320.x or newer. Detailed information regarding patches is available in the ICS-CERT advisory ICSA-24-338-01 published by CISA.

Who is affected

Ruijie Reyee OS in versions from 2.206.x to versions below 2.320.x (not inclusive)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Ruijienetworks Reyee Os

    OS
    Ruijienetworks
    2.206.0 – 2.320.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-53881CRITICAL9.2PL ✓same product

ReyeeOS: RCE przez niezaszyfrowaną komunikację CWMP (MitM)

CVE-2024-52324CRITICAL9.2PL ✓same product

RCE poprzez niebezpieczną funkcję w Ruijie Reyee OS — wykonanie dowolnych poleceń OS

CVE-2024-47547CRITICAL9.3PL ✓same product

Słaby mechanizm zmiany hasła w Ruijie Reyee OS — podatność na brute force

CVE-2024-46874CRITICAL9.2PL ✓same product

Ruijie Reyee OS — nieautoryzowane polecenia do urządzeń przez MQTT

CVE-2025-56077HIGH8.8same product

OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary co...