CVE-2024-6199 Details
Description
An unauthenticated attacker on the WAN interface, with the ability to intercept Dynamic DNS (DDNS) traffic between DDNS services and the modem, could manipulate specific responses to include code that forces a buffer overflow on the modem. Customers that have not enabled Dynamic DNS on their modem are not vulnerable.
A remote code execution vulnerability has been identified in Viasat RM5110, RM5111, RG1100, EG1000, and EG1020 modems, all running versions through 4.3.0.2. The vulnerability allows an unauthenticated attacker on the WAN interface to intercept and manipulate Dynamic DNS (DDNS) traffic, causing a buffer overflow on the modem. This issue affects customers who have enabled DDNS on their modem.
Customers should ensure their devices are online to receive the automated update from Viasat. After the update, verify the device is running version 4.3.0.3 using the administrative interface.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 25, 2025CISA-ADP
Assessed Apr 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.onekey.com/resource/security-advisory-rce-on-viasat-modems-cve-2024-6199 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Viasat RM5110 | <= 4.3.0.2 |
CPE
Remediation
| |
| Viasat RM5111 | <= 4.3.0.2 |
CPE
Remediation
| |
| Viasat RG1100 | <= 4.3.0.2 |
CPE
Remediation
| |
| Viasat EG1000 | <= 4.3.0.2 |
CPE
Remediation
| |
| Viasat EG1020 | <= 4.3.0.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 25, 2025 | New CVE Received | [email protected] |
Volerion