CVE-2024-29082
8.8
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: ics-cert@hq.dhs.gov (Secondary)
Description
Improper access control vulnerability affecting Vonets
industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9
and prior, enables an unauthenticated remote attacker to bypass
authentication and factory reset the device via unprotected goform
endpoints.
Affected (14)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var1200 H | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var1200 L | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var600 H | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11ac | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g 500s | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vbg1200 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11s 5g | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11s | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var11n 300 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g 300 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11n 300 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g 500 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vga 1000 | All versions |
References (1)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.