PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-45722 Ruijie CVE debrief

Ruijie Reyee OS versions 2.206.x through 2.319.x contain a weak credential mechanism that allows attackers to calculate MQTT credentials. The vulnerability was disclosed by CISA on December 3, 2024, with an update on December 10, 2024 revising CVSS scores. Ruijie reports the issue has been fixed on the cloud side with no end-user action required. The vulnerability carries a MEDIUM severity rating with a CVSS 3.1 score of 5.9, reflecting network attack vector with high attack complexity but no required privileges or user interaction, leading to high confidentiality impact.

Vendor
Ruijie
Product
Reyee OS
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2024-12-03
Original CVE updated
2024-12-10
Advisory published
2024-12-03
Advisory updated
2024-12-10

Who should care

Organizations operating Ruijie Reyee OS devices in versions 2.206.x through 2.319.x, particularly those using MQTT for device management or telemetry. Security teams managing IoT/OT networks and industrial control systems should assess exposure and verify cloud-side remediation status.

Technical summary

The vulnerability exists in Ruijie Reyee OS versions 2.206.x through 2.319.x where MQTT credentials can be calculated by attackers due to a weak credential generation mechanism. This is a confidentiality-only vulnerability with high attack complexity. The attack requires network access but no authentication. Ruijie has implemented a cloud-side fix, meaning affected devices connecting to Ruijie cloud services should receive remediation automatically without requiring manual firmware updates.

Defensive priority

medium

Recommended defensive actions

  • Verify device firmware version against affected range 2.206.x to 2.319.x
  • Confirm cloud-side fix has been applied to managed devices
  • Monitor MQTT traffic for unauthorized credential usage
  • Apply network segmentation for IoT/OT devices per CISA ICS recommended practices
  • Review CISA guidance on industrial control system defense in depth

Evidence notes

The source advisory confirms affected versions as 2.206.x up to but not including 2.320.x. Ruijie states cloud-side remediation has been applied. CVSS 3.1 vector: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. CVSS 4.0 vector also provided in source.

Official resources

CISA published advisory ICSA-24-338-01 on December 3, 2024, with Update A on December 10, 2024 adjusting CVSS scores.