CVE-2024-37023
9.4
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: ics-cert@hq.dhs.gov (Secondary)
Description
Multiple OS command injection vulnerabilities affecting Vonets
industrial wifi bridge relays and wifi bridge repeaters, software
versions 3.3.23.6.9 and prior, enable an authenticated remote attacker
to execute arbitrary OS commands via various endpoint parameters.
Affected (14)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var1200 H | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var1200 L | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var600 H | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11ac | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g 500s | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vbg1200 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11s 5g | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11s | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var11n 300 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g 300 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11n 300 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g 500 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vga 1000 | All versions |
References (1)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.