Improper Authorization Vulnerability in Ruijie RG-NBS2009G-P
CVE-2024-2641
Key Information:
- Vendor
- Ruijie
- Status
- Vendor
- CVE Published:
- 19 March 2024
Badges
Summary
A critical vulnerability has been identified in the Ruijie RG-NBS2009G-P switch, specifically within the /system/passwdManage.htm component. This flaw pertains to improper authorization, which may allow an attacker to exploit the system remotely. The vulnerability poses significant security risks, especially since it has been publicly disclosed. Users are encouraged to review their security posture and apply any available updates or mitigations to safeguard against potential attacks.
Affected Version(s)
RG-NBS2009G-P 20240305
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved