PatchSiren cyber security CVE debrief
CVE-2024-51727 Ruijie CVE debrief
A session invalidation vulnerability in Ruijie Reyee OS versions 2.206.x through 2.319.x allows authenticated attackers with high privileges to terminate legitimate user sessions, causing denial-of-service conditions on affected accounts. The vulnerability stems from a product feature that lacks proper session management controls. CISA published this advisory on December 3, 2024, with an update on December 10, 2024 revising CVSS scores. The vendor has deployed cloud-based fixes requiring no end-user action.
- Vendor
- Ruijie
- Product
- Reyee OS
- CVSS
- MEDIUM 4.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-03
- Original CVE updated
- 2024-12-10
- Advisory published
- 2024-12-03
- Advisory updated
- 2024-12-10
Who should care
Organizations operating Ruijie Reyee OS in industrial control or operational technology environments, particularly those with remote administrative access requirements and multi-user account configurations
Technical summary
Ruijie Reyee OS contains a session management feature that permits high-privilege authenticated attackers to invalidate legitimate user sessions remotely. The vulnerability affects versions 2.206.x through 2.319.x and results in denial-of-service conditions on targeted user accounts. Network attack vector with low complexity and high privilege requirements. No confidentiality or integrity impact; availability impact rated high. Vendor has implemented cloud-based remediation.
Defensive priority
medium
Recommended defensive actions
- Verify Reyee OS device firmware version is 2.320.x or later, or confirm cloud-managed devices have received automatic updates
- Monitor administrative account sessions for unexpected terminations or anomalous session management activity
- Review access controls to ensure high-privilege accounts follow least-privilege principles
- Apply CISA ICS recommended practices for network segmentation of OT/ICS devices
- Document and audit session management configurations in Reyee OS deployments
Evidence notes
CISA CSAF source confirms affected versions as 2.206.x up to but not including 2.320.x. CVSS 3.1 vector AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H yields score 4.9 (Medium). Vendor remediation states cloud-based fix deployed with no user action required.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-51727 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-51727
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-51727 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-51727
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-338-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.