CVE-2024-42001
6.1
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: ics-cert@hq.dhs.gov (Secondary)
Description
An improper authentication vulnerability affecting Vonets
industrial wifi bridge relays and wifi bridge repeaters, software versions
3.3.23.6.9 and prior enables an unauthenticated remote attacker to
bypass authentication via a specially crafted direct request when
another user has an active session.
Affected (14)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var1200 H | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var1200 L | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var600 H | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11ac | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g 500s | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vbg1200 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11s 5g | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11s | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Var11n 300 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g 300 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11n 300 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vap11g 500 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.3.23.6.9 |
| Running on/with | Platform Versions |
|---|---|
Vonets Vga 1000 | All versions |
References (1)
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.