Remote Code Execution Vulnerability in AutomationDirect C-More EA9 Software
CVE-2024-11610

Currently unrated

Key Information:

Vendor
CVE Published:
30 January 2025

What is CVE-2024-11610?

A file parsing vulnerability exists in AutomationDirect's C-More EA9 software, specifically related to the EAP9 file format. This issue stems from inadequate validation of user-supplied data, leading to potential memory corruption. Attackers can exploit this vulnerability remotely by luring users into visiting a malicious page or opening a compromised file, which could allow them to execute arbitrary code within the context of the current process. This vulnerability underlines the importance of data validation and secure coding practices.

Affected Version(s)

C-More EA9 6.78

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.