CVE-2024-42001
HIGHDescription
An improper authentication vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior enables an unauthenticated remote attacker to bypass authentication via a specially crafted direct request when another user has an active session.
Is your site exposed to CVE-2024-42001?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| vonets | var1200-h_firmware |
| vonets | var1200-h |
| vonets | var1200-l_firmware |
| vonets | var1200-l |
| vonets | var600-h_firmware |
| vonets | var600-h |
| vonets | vap11ac_firmware |
| vonets | vap11ac |
| vonets | vap11g-500s_firmware |
| vonets | vap11g-500s |
| vonets | vbg1200_firmware |
| vonets | vbg1200 |
| vonets | vap11s-5g_firmware |
| vonets | vap11s-5g |
| vonets | vap11s_firmware |
| vonets | vap11s |
| vonets | var11n-300_firmware |
| vonets | var11n-300 |
| vonets | vap11g-300_firmware |
| vonets | vap11g-300 |
| vonets | vap11n-300_firmware |
| vonets | vap11n-300 |
| vonets | vap11g_firmware |
| vonets | vap11g |
| vonets | vap11g-500_firmware |
| vonets | vap11g-500 |
| vonets | vga-1000_firmware |
| vonets | vga-1000 |
References
Other References
Frequently Asked Questions
What is CVE-2024-42001? +
How severe is CVE-2024-42001? +
What products are affected by CVE-2024-42001? +
How do I check if I'm vulnerable to CVE-2024-42001? +
Related Vulnerabilities
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access to sensitive information.
The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not protected by an authorization scheme. An unauthenticated …
In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) an unauthorised user can view configuration files by directly …
Improper permission control vulnerability in the OXARI ServiceDesk application could allow an attacker using a guest access or an unprivileged …
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an …
Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker sends a …