CVE-2024-47079

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Oct 7, 2024
Updated: Oct 10, 2024
CWE ID 345

Summary

CVE-2024-47079 is a vulnerability affecting the Meshtastic mesh network's open source firmware. The remote hardware module in the firmware lacks adequate validation checks for remote hardware control messages, potentially allowing unauthorized access and control. This issue has been fixed in version 2.5.1, and users are strongly encouraged to upgrade as soon as possible. Unfortunately, there are no known workarounds for this vulnerability, making an immediate upgrade the most effective mitigation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Meshtastic Firmware

Affected Vendors

  • Meshtastic LLC