CVE-2024-42001

HIGH

Vonets - Auth Bypass

Title source: llm
STIX 2.1

Description

An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior enables an unauthenticated remote attacker to bypass authentication via a specially crafted direct request when another user has an active session.

Scores

CVSS v3 8.6
EPSS 0.0017
EPSS Percentile 37.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-425
Status published
Products (14)
vonets/vap11ac_firmware < 3.3.23.6.9
vonets/vap11g-300_firmware < 3.3.23.6.9
vonets/vap11g-500_firmware < 3.3.23.6.9
vonets/vap11g-500s_firmware < 3.3.23.6.9
vonets/vap11g_firmware < 3.3.23.6.9
vonets/vap11n-300_firmware < 3.3.23.6.9
vonets/vap11s-5g_firmware < 3.3.23.6.9
vonets/vap11s_firmware < 3.3.23.6.9
vonets/var11n-300_firmware < 3.3.23.6.9
vonets/var1200-h_firmware < 3.3.23.6.9
... and 4 more
Published Aug 12, 2024
Tracked Since Feb 18, 2026