Leftover Debug Code Vulnerability in Telnet Diagnostic Interface of AutomationDirect P3-550E 1.2.10.9
CVE-2024-21785

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
28 May 2024

What is CVE-2024-21785?

A vulnerability in the Telnet Diagnostic Interface functionality of AutomationDirect's P3-550E 1.2.10.9 results from leftover debug code, which can be exploited by attackers. By sending a carefully crafted series of network requests, an attacker may gain unauthorized access to the system. This type of vulnerability underscores the importance of removing debug code in production environments to prevent potential exploitation.

Affected Version(s)

P3-550E 1.2.10.9

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Matt Wiseman of Cisco Talos.
.