CVE-2024-23962

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 31, 2025
CWE ID 862

Summary

CVE-2024-23962 is a newly discovered vulnerability affecting Alpine Halo9 devices. It enables unauthenticated remote attackers to disclose sensitive information by exploiting a flaw in the DLT interface, which listens on the default TCP port 3490. This vulnerability is significant as it does not require authentication, increasing the risk of unauthorized access. An attacker can leverage this vulnerability in conjunction with other exploits to execute arbitrary code within the device.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share