Remote Information Disclosure in Alpine Halo9 Devices by Vendor ABC
CVE-2024-23962

5.3MEDIUM

Key Information:

Vendor

Alpine

Status
Vendor
CVE Published:
31 January 2025

What is CVE-2024-23962?

This issue allows unauthorized remote access to sensitive information on Alpine Halo9 devices due to a flaw within the DLT interface, which operates on TCP port 3490. The vulnerability arises from the absence of required authentication, enabling attackers to exploit it and potentially execute arbitrary code by chaining it with other vulnerabilities. Users of affected firmware versions are urged to review their security measures to mitigate the risks of unauthorized access.

Affected Version(s)

Halo9 all versions

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.