Remote Information Disclosure in Alpine Halo9 Devices by Vendor ABC
CVE-2024-23962
5.3MEDIUM
What is CVE-2024-23962?
This issue allows unauthorized remote access to sensitive information on Alpine Halo9 devices due to a flaw within the DLT interface, which operates on TCP port 3490. The vulnerability arises from the absence of required authentication, enabling attackers to exploit it and potentially execute arbitrary code by chaining it with other vulnerabilities. Users of affected firmware versions are urged to review their security measures to mitigate the risks of unauthorized access.
Affected Version(s)
Halo9 all versions