Ruijie Reyee OS Server-Side Request Forgery
Published Dec 6, 2024
9.3
CRITICALCVSS 4.0
EPSS 0.60%
Description
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x could give attackers the ability to force Ruijie's proxy servers to perform any request the attackers choose. Using this, attackers could access internal services used by Ruijie and their internal cloud infrastructure via AWS cloud metadata services.
Affected products
-
- Version 2.206.xStatusaffectedConstraints<2.320.x
- Version
- ≥ 2.206.0 · < 2.320.0
-
- Version 2.206.xStatusaffectedConstraints<2.320.x
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Ruijie reports that the issues have been fixed on the cloud and no action is needed by end users. However, CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities, such as:
* Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01 . * Locate control system networks and remote devices behind firewalls and isolating them from business networks. * When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Dec 6, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.60% (0.00601) | 46.88th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.59% (0.00593) | 43.51th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.06% (0.00062) | 16.60th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00043) | 10.81th | v3 (v2023.03.01) |
| Dec 7, 2024 | 0.04% (0.00043) | 10.60th | v3 (v2023.03.01) |
References (1)
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01 Third Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-01 | Third Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.