CVE-2024-48874

CRITICAL

Ruijie Reyee OS 2.206.x-2.319.x - Server-Side Request Forgery via Proxy Server

Title source: llm
STIX 2.1

Description

Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud infrastructure via AWS cloud metadata services.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01

Scores

CVSS v3 9.8
EPSS 0.0059
EPSS Percentile 43.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-918
Status published
Products (1)
ruijienetworks/reyee_os 2.206.0 - 2.320.0
Published Dec 06, 2024
Tracked Since Feb 18, 2026