PatchSiren cyber security CVE debrief
CVE-2024-51727 Ruijie CVE debrief
A session invalidation vulnerability in Ruijie Reyee OS versions 2.206.x through 2.319.x allows authenticated attackers with high privileges to terminate legitimate user sessions, causing denial-of-service conditions on affected accounts. The vulnerability stems from a product feature that lacks proper session management controls. CISA published this advisory on December 3, 2024, with an update on December 10, 2024 revising CVSS scores. The vendor has deployed cloud-based fixes requiring no end-user action.
- Vendor
- Ruijie
- Product
- Reyee OS
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-03
- Original CVE updated
- 2024-12-10
- Advisory published
- 2024-12-03
- Advisory updated
- 2024-12-10
Who should care
Organizations operating Ruijie Reyee OS in industrial control or operational technology environments, particularly those with remote administrative access requirements and multi-user account configurations
Technical summary
Ruijie Reyee OS contains a session management feature that permits high-privilege authenticated attackers to invalidate legitimate user sessions remotely. The vulnerability affects versions 2.206.x through 2.319.x and results in denial-of-service conditions on targeted user accounts. Network attack vector with low complexity and high privilege requirements. No confidentiality or integrity impact; availability impact rated high. Vendor has implemented cloud-based remediation.
Defensive priority
medium
Recommended defensive actions
- Verify Reyee OS device firmware version is 2.320.x or later, or confirm cloud-managed devices have received automatic updates
- Monitor administrative account sessions for unexpected terminations or anomalous session management activity
- Review access controls to ensure high-privilege accounts follow least-privilege principles
- Apply CISA ICS recommended practices for network segmentation of OT/ICS devices
- Document and audit session management configurations in Reyee OS deployments
Evidence notes
CISA CSAF source confirms affected versions as 2.206.x up to but not including 2.320.x. CVSS 3.1 vector AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H yields score 4.9 (Medium). Vendor remediation states cloud-based fix deployed with no user action required.
Official resources
-
CVE-2024-51727 CVE record
CVE.org
-
CVE-2024-51727 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
CISA ICS Advisory ICSA-24-338-01 published December 3, 2024; Update A published December 10, 2024