TCP Session Hijacking Vulnerability Affects Ruijie Routers
CVE-2023-30308

6.5MEDIUM

Key Information:

Vendor
Ruijie
Vendor
CVE Published:
28 May 2024

Summary

A vulnerability identified in several Ruijie router models allows attackers to intercept and hijack TCP sessions. This exploitation can facilitate unauthorized access to network resources and result in denial of service conditions. Attackers may trigger this flaw by exploiting sequence number leakage, particularly in environments with NAT-enabled Wi-Fi networks. Security measures should be implemented promptly to mitigate the risks associated with affected devices.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.