PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-51727 Ruijie CVE debrief

A session invalidation vulnerability in Ruijie Reyee OS versions 2.206.x through 2.319.x allows authenticated attackers with high privileges to terminate legitimate user sessions, causing denial-of-service conditions on affected accounts. The vulnerability stems from a product feature that lacks proper session management controls. CISA published this advisory on December 3, 2024, with an update on December 10, 2024 revising CVSS scores. The vendor has deployed cloud-based fixes requiring no end-user action.

Vendor
Ruijie
Product
Reyee OS
CVSS
MEDIUM 4.9
CISA KEV
Not listed in stored evidence
Original CVE published
2024-12-03
Original CVE updated
2024-12-10
Advisory published
2024-12-03
Advisory updated
2024-12-10

Who should care

Organizations operating Ruijie Reyee OS in industrial control or operational technology environments, particularly those with remote administrative access requirements and multi-user account configurations

Technical summary

Ruijie Reyee OS contains a session management feature that permits high-privilege authenticated attackers to invalidate legitimate user sessions remotely. The vulnerability affects versions 2.206.x through 2.319.x and results in denial-of-service conditions on targeted user accounts. Network attack vector with low complexity and high privilege requirements. No confidentiality or integrity impact; availability impact rated high. Vendor has implemented cloud-based remediation.

Defensive priority

medium

Recommended defensive actions

  • Verify Reyee OS device firmware version is 2.320.x or later, or confirm cloud-managed devices have received automatic updates
  • Monitor administrative account sessions for unexpected terminations or anomalous session management activity
  • Review access controls to ensure high-privilege accounts follow least-privilege principles
  • Apply CISA ICS recommended practices for network segmentation of OT/ICS devices
  • Document and audit session management configurations in Reyee OS deployments

Evidence notes

CISA CSAF source confirms affected versions as 2.206.x up to but not including 2.320.x. CVSS 3.1 vector AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H yields score 4.9 (Medium). Vendor remediation states cloud-based fix deployed with no user action required.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-51727 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-51727

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-51727 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-51727

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-338-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.