CVE-2024-3764
Last modified
CVE-2024-3764 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. ** DISPUTED ** A vulnerability classified as problematic has been found in Tuya SDK up to 5.0.x. Affected is an unknown function of the component MQTT Packet Handler. EPSS estimates a 0.59% chance of exploitation in the next 30 days.
Description
** DISPUTED ** A vulnerability classified as problematic has been found in Tuya SDK up to 5.0.x. Affected is an unknown function of the component MQTT Packet Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. Upgrading to version 5.1.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-260604. NOTE: The vendor explains that a malicious actor would have to crack TLS first or use a legitimate login to initiate the attack.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-3764?
How severe is CVE-2024-3764?
How do I fix CVE-2024-3764?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-37632TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to cont…9.8
- CVE-2024-37633TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to cont…8.8
- CVE-2024-37634TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to cont…9.8
- CVE-2024-37635TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to cont…9.8
- CVE-2024-37637TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to cont…9.8
- CVE-2024-37639TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to cont…8.8
- CVE-2024-37640TOTOLINK A3700R V9.1.2u.6165_20211012 was discovered to cont…8.8
- CVE-2024-37641TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain…8.8
- CVE-2024-37642TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain…9.1
- CVE-2024-37643TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain…8.8
- CVE-2024-37644TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain…8.8
- CVE-2024-37645TRENDnet TEW-814DAP v1_(FW1.01B01) was discovered to contain…8.8
Are you affected by CVE-2024-3764?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
