MEDIUM · 4.3

CVE-2024-24782

An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are separated by VLAN.

Vulnerability Description

An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are separated by VLAN.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HimaF30 03X Yy \(Com\) Firmware<= 24.14
HimaF30 03X Yy \(Com\)-
HimaF30 03X Yy \(Cpu\) Firmware<= 18.6
HimaF30 03X \(Cpu\) Yy-
HimaF35 03X Yy \(Com\) Firmware<= 24.14
HimaF35 03X Yy \(Com\) -
HimaF35 03X Yy \(Cpu\) Firmware<= 18.6
HimaF35 03X Yy \(Cpu\)-
HimaF60 Cpu 03X Yy \(Com\) Firmware<= 24.14
HimaF60 Cpu 03X Yy \(Com\)-
HimaF60 Cpu 03X Yy \(Cpu\) Firmware<= 18.6
HimaF60 Cpu 03X Yy \(Cpu\)-
HimaF-Com 01 Firmware<= 14.12
HimaF-Com 01-
HimaF-Cpu 01 Firmware<= 14.16
HimaF-Cpu 01-
HimaX-Com 01 E Yy Firmware<= 15.14
HimaX-Com 01 E Yy-
HimaX-Com 01 Yy Firmware<= 14.12
HimaX-Com 01 Yy-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-24782?

CVE-2024-24782 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An unauthenticated attacker can send a ping request from one network to another through an error in the origin verification even though the ports are separated by VLAN.

How severe is CVE-2024-24782?

CVE-2024-24782 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-24782?

Check the references section above for vendor advisories and patch information. Affected products include: Hima F30 03X Yy \(Com\) Firmware, Hima F30 03X Yy \(Com\), Hima F30 03X Yy \(Cpu\) Firmware, Hima F30 03X \(Cpu\) Yy, Hima F35 03X Yy \(Com\) Firmware.