CVE-2024-8889
Vulnerability in CIRCUTOR TCP2RS+ firmware version 1.3b, which could allow an attacker to modify any configuration value, even if the device has the user/password authentication option enabled, without authentication by sending packets through the UDP protocol and port 2000, deconfiguring the device and thus disabling its use. This equipment is at the end of its useful life cycle.
Published:Sep 18, 2024
Last Modified:Oct 7, 2024
EPS:Sep 18, 2024
EPSS Score:0.00191
CVSS Score:9.3
Affected Products
Vendor
Product
Action
Vendor
Circutor
Product
Circutor Tcp2rs Plus
Circutor
Circutor Tcp2rs Plus
Vendor
Circutor
Product
Tcp2rs\+
Circutor
Tcp2rs\+
Vendor
Circutor
Product
Tcp2rs\+ Firmware
Circutor
Tcp2rs\+ Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
