CVE-2024-6199

HIGH

Modem <unknown> - Buffer Overflow

Title source: llm
STIX 2.1

Description

An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem. Customers that have not enabled Dynamic DNS on their modem are not vulnerable.

References (1)

Core 1
Core References
Various Sources third-party-advisory technical-description
https://www.onekey.com/resource/security-advisory-rce-on-viasat-modems-cve-2024-6199

Scores

CVSS v4 7.7
EPSS 0.0009
EPSS Percentile 26.2%
CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/S:N/AU:N/R:U/V:D/RE:M/U:Red

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-120
Status published
Products (5)
Viasat/EG1000 < 4.3.0.2
Viasat/EG1020 < 4.3.0.2
Viasat/RG1100 < 4.3.0.2
ViaSat/RM5110 < 4.3.0.2
ViaSat/RM5111 < 4.3.0.2
Published Apr 25, 2025
Tracked Since Feb 18, 2026