SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2024-39815

Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to cause a denial of service.

CRITICAL 9.4EPSS 0.77%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Improper check or handling of exceptional conditions vulnerability affecting Vonets industrial wifi bridge relays and wifi bridge repeaters, software versions 3.3.23.6.9 and prior, enable an unauthenticated remote attacker to cause a denial of service. A specially-crafted HTTP request to pre-authentication resources can crash the service.

CVSS 4.0
9.4 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
0.77% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-703
Affected
vonets/var1200-h firmware · vonets/var1200-l firmware · vonets/var600-h firmware · vonets/vap11ac firmware · vonets/vap11g-500s firmware · vonets/vbg1200 firmware · vonets/vap11s-5g firmware · vonets/vap11s firmware · vonets/var11n-300 firmware · vonets/vap11g-300 firmware · vonets/vap11n-300 firmware · vonets/vap11g firmware · vonets/vap11g-500 firmware · vonets/vga-1000 firmware
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.