PatchSiren cyber security CVE debrief
CVE-2024-45722 Ruijie CVE debrief
Ruijie Reyee OS versions 2.206.x through 2.319.x contain a weak credential mechanism that allows attackers to calculate MQTT credentials. The vulnerability was disclosed by CISA on December 3, 2024, with an update on December 10, 2024 revising CVSS scores. Ruijie reports the issue has been fixed on the cloud side with no end-user action required. The vulnerability carries a MEDIUM severity rating with a CVSS 3.1 score of 5.9, reflecting network attack vector with high attack complexity but no required privileges or user interaction, leading to high confidentiality impact.
- Vendor
- Ruijie
- Product
- Reyee OS
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-03
- Original CVE updated
- 2024-12-10
- Advisory published
- 2024-12-03
- Advisory updated
- 2024-12-10
Who should care
Organizations operating Ruijie Reyee OS devices in versions 2.206.x through 2.319.x, particularly those using MQTT for device management or telemetry. Security teams managing IoT/OT networks and industrial control systems should assess exposure and verify cloud-side remediation status.
Technical summary
The vulnerability exists in Ruijie Reyee OS versions 2.206.x through 2.319.x where MQTT credentials can be calculated by attackers due to a weak credential generation mechanism. This is a confidentiality-only vulnerability with high attack complexity. The attack requires network access but no authentication. Ruijie has implemented a cloud-side fix, meaning affected devices connecting to Ruijie cloud services should receive remediation automatically without requiring manual firmware updates.
Defensive priority
medium
Recommended defensive actions
- Verify device firmware version against affected range 2.206.x to 2.319.x
- Confirm cloud-side fix has been applied to managed devices
- Monitor MQTT traffic for unauthorized credential usage
- Apply network segmentation for IoT/OT devices per CISA ICS recommended practices
- Review CISA guidance on industrial control system defense in depth
Evidence notes
The source advisory confirms affected versions as 2.206.x up to but not including 2.320.x. Ruijie states cloud-side remediation has been applied. CVSS 3.1 vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. CVSS 4.0 vector also provided in source.
Official resources
-
CVE-2024-45722 CVE record
CVE.org
-
CVE-2024-45722 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
CISA published advisory ICSA-24-338-01 on December 3, 2024, with Update A on December 10, 2024 adjusting CVSS scores.