CVE-2024-42001

An improper authentication vulnerability affecting Vonets





 

 industrial wifi bridge relays and wifi bridge repeaters, software versions 
3.3.23.6.9 and prior enables an unauthenticated remote attacker to 
bypass authentication via a specially crafted direct request when 
another user has an active session.
Forced Browsing
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
icscertCNA
8.6 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
VendorProductVersion
vonetsvar1200-h_firmware
𝑥
≤ 3.3.23.6.9
vonetsvar1200-l_firmware
𝑥
≤ 3.3.23.6.9
vonetsvar600-h_firmware
𝑥
≤ 3.3.23.6.9
vonetsvap11ac_firmware
𝑥
≤ 3.3.23.6.9
vonetsvap11g-500s_firmware
𝑥
≤ 3.3.23.6.9
vonetsvbg1200_firmware
𝑥
≤ 3.3.23.6.9
vonetsvap11s-5g_firmware
𝑥
≤ 3.3.23.6.9
vonetsvap11s_firmware
𝑥
≤ 3.3.23.6.9
vonetsvar11n-300_firmware
𝑥
≤ 3.3.23.6.9
vonetsvap11g-300_firmware
𝑥
≤ 3.3.23.6.9
vonetsvap11n-300_firmware
𝑥
≤ 3.3.23.6.9
vonetsvap11g_firmware
𝑥
≤ 3.3.23.6.9
vonetsvap11g-500_firmware
𝑥
≤ 3.3.23.6.9
vonetsvga-1000_firmware
𝑥
≤ 3.3.23.6.9
𝑥
= Vulnerable software versions