PatchSiren cyber security CVE debrief
CVE-2024-45722 Ruijie CVE debrief
Ruijie Reyee OS versions 2.206.x through 2.319.x contain a weak credential mechanism that allows attackers to calculate MQTT credentials. The vulnerability was disclosed by CISA on December 3, 2024, with an update on December 10, 2024 revising CVSS scores. Ruijie reports the issue has been fixed on the cloud side with no end-user action required. The vulnerability carries a MEDIUM severity rating with a CVSS 3.1 score of 5.9, reflecting network attack vector with high attack complexity but no required privileges or user interaction, leading to high confidentiality impact.
- Vendor
- Ruijie
- Product
- Reyee OS
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-03
- Original CVE updated
- 2024-12-10
- Advisory published
- 2024-12-03
- Advisory updated
- 2024-12-10
Who should care
Organizations operating Ruijie Reyee OS devices in versions 2.206.x through 2.319.x, particularly those using MQTT for device management or telemetry. Security teams managing IoT/OT networks and industrial control systems should assess exposure and verify cloud-side remediation status.
Technical summary
The vulnerability exists in Ruijie Reyee OS versions 2.206.x through 2.319.x where MQTT credentials can be calculated by attackers due to a weak credential generation mechanism. This is a confidentiality-only vulnerability with high attack complexity. The attack requires network access but no authentication. Ruijie has implemented a cloud-side fix, meaning affected devices connecting to Ruijie cloud services should receive remediation automatically without requiring manual firmware updates.
Defensive priority
medium
Recommended defensive actions
- Verify device firmware version against affected range 2.206.x to 2.319.x
- Confirm cloud-side fix has been applied to managed devices
- Monitor MQTT traffic for unauthorized credential usage
- Apply network segmentation for IoT/OT devices per CISA ICS recommended practices
- Review CISA guidance on industrial control system defense in depth
Evidence notes
The source advisory confirms affected versions as 2.206.x up to but not including 2.320.x. Ruijie states cloud-side remediation has been applied. CVSS 3.1 vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. CVSS 4.0 vector also provided in source.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-45722 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-45722
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-45722 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-45722
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-338-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.