CVE-2024-47791: Ruijie Reyee OS Improper Neutralization of Wildcards or Matching Symbols

7.5 CVSS

Description

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could allow an attacker to subscribe to partial possible topics in Ruijie MQTT broker, and receive partial messages being sent to and from devices.

Classification

CVE ID: CVE-2024-47791

CVSS Base Severity: HIGH

CVSS Base Score: 7.5

Affected Products

Vendor: Ruijie

Product: Reyee OS

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 19.3% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01

Timeline