CVE-2024-24781

An unauthenticated remote attacker can use an uncontrolled resource consumption vulnerability to DoS the affected devices through excessive traffic on a single ethernet port. 
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2024-013 Mitigation Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hima:f30_03x_yy_\(com\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f30_03x_yy_\(com\):-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hima:f30_03x_yy_\(cpu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f30_03x_\(cpu\)_yy:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:hima:f35_03x_yy_\(com\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f35_03x_yy_\(com\)_:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:hima:f35_03x_yy_\(cpu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f35_03x_yy_\(cpu\):-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:hima:f60_cpu_03x_yy_\(com\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f60_cpu_03x_yy_\(com\):-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:hima:f60_cpu_03x_yy_\(cpu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f60_cpu_03x_yy_\(cpu\):-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:hima:f-com_01_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f-com_01:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:hima:f-cpu_01_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f-cpu_01:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:hima:x-com_01_e_yy_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:x-com_01_e_yy:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:hima:x-com_01_yy_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:x-com_01_yy:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:hima:x-cpu_01_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:x-cpu_01:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:hima:x-cpu_31_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:x-cpu_31:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:hima:x-sb_01_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:x-sb_01:-:*:*:*:*:*:*:*

History

18 Oct 2024, 19:00

Type Values Removed Values Added
First Time Hima x-cpu 31 Firmware
Hima f35 03x Yy \(com\)
Hima x-sb 01 Firmware
Hima x-cpu 01
Hima f30 03x Yy \(com\)
Hima f-cpu 01
Hima x-com 01 Yy
Hima x-cpu 01 Firmware
Hima f35 03x Yy \(com\) Firmware
Hima f-com 01
Hima x-com 01 E Yy
Hima x-sb 01
Hima f60 Cpu 03x Yy \(cpu\) Firmware
Hima x-com 01 Yy Firmware
Hima f60 Cpu 03x Yy \(cpu\)
Hima f35 03x Yy \(cpu\)
Hima f35 03x Yy \(cpu\) Firmware
Hima f30 03x \(cpu\) Yy
Hima f60 Cpu 03x Yy \(com\)
Hima x-com 01 E Yy Firmware
Hima f30 03x Yy \(cpu\) Firmware
Hima f-com 01 Firmware
Hima f30 03x Yy \(com\) Firmware
Hima
Hima f-cpu 01 Firmware
Hima f60 Cpu 03x Yy \(com\) Firmware
Hima x-cpu 31
Summary
  • (es) Un atacante remoto no autenticado puede utilizar una vulnerabilidad de consumo de recursos incontrolado para DoS en los dispositivos afectados a través de un tráfico excesivo en un único puerto Ethernet.
References () https://cert.vde.com/en/advisories/VDE-2024-013 - () https://cert.vde.com/en/advisories/VDE-2024-013 - Mitigation, Third Party Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:hima:x-cpu_31_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hima:x-sb_01_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f-cpu_01:-:*:*:*:*:*:*:*
cpe:2.3:h:hima:f-com_01:-:*:*:*:*:*:*:*
cpe:2.3:h:hima:x-sb_01:-:*:*:*:*:*:*:*
cpe:2.3:o:hima:f-cpu_01_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:x-cpu_31:-:*:*:*:*:*:*:*
cpe:2.3:h:hima:f30_03x_\(cpu\)_yy:-:*:*:*:*:*:*:*
cpe:2.3:o:hima:f-com_01_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f60_cpu_03x_yy_\(cpu\):-:*:*:*:*:*:*:*
cpe:2.3:h:hima:f35_03x_yy_\(cpu\):-:*:*:*:*:*:*:*
cpe:2.3:h:hima:x-com_01_yy:-:*:*:*:*:*:*:*
cpe:2.3:h:hima:f30_03x_yy_\(com\):-:*:*:*:*:*:*:*
cpe:2.3:o:hima:f60_cpu_03x_yy_\(com\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f60_cpu_03x_yy_\(com\):-:*:*:*:*:*:*:*
cpe:2.3:h:hima:x-com_01_e_yy:-:*:*:*:*:*:*:*
cpe:2.3:o:hima:f35_03x_yy_\(com\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hima:x-com_01_yy_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hima:f30_03x_yy_\(com\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:x-cpu_01:-:*:*:*:*:*:*:*
cpe:2.3:o:hima:x-cpu_01_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:hima:f35_03x_yy_\(com\)_:-:*:*:*:*:*:*:*
cpe:2.3:o:hima:f35_03x_yy_\(cpu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hima:x-com_01_e_yy_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hima:f30_03x_yy_\(cpu\)_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:hima:f60_cpu_03x_yy_\(cpu\)_firmware:*:*:*:*:*:*:*:*

13 Feb 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-13 14:15

Updated : 2024-10-18 19:00


NVD link : CVE-2024-24781

Mitre link : CVE-2024-24781

CVE.ORG link : CVE-2024-24781


JSON object : View

Products Affected

hima

  • f60_cpu_03x_yy_\(cpu\)_firmware
  • f35_03x_yy_\(com\)_firmware
  • f60_cpu_03x_yy_\(com\)
  • f-cpu_01
  • f-cpu_01_firmware
  • x-sb_01
  • f35_03x_yy_\(cpu\)
  • f30_03x_\(cpu\)_yy
  • f-com_01_firmware
  • f30_03x_yy_\(com\)_firmware
  • x-sb_01_firmware
  • x-com_01_yy
  • f30_03x_yy_\(com\)
  • x-com_01_yy_firmware
  • x-cpu_31
  • f60_cpu_03x_yy_\(cpu\)
  • x-cpu_31_firmware
  • x-cpu_01_firmware
  • x-com_01_e_yy
  • x-cpu_01
  • f60_cpu_03x_yy_\(com\)_firmware
  • f35_03x_yy_\(cpu\)_firmware
  • f30_03x_yy_\(cpu\)_firmware
  • f-com_01
  • x-com_01_e_yy_firmware
  • f35_03x_yy_\(com\)_
CWE
NVD-CWE-noinfo CWE-400

Uncontrolled Resource Consumption