Arbitrary Code Execution Vulnerability in AutomationDirect P3-550E 1.2.10.9 Due to Code Injection
CVE-2024-23601

9.8CRITICAL

Key Information:

Status
Vendor
CVE Published:
28 May 2024

What is CVE-2024-23601?

A vulnerability exists within the scan_lib.bin functionality of AutomationDirect's P3-550E, which allows for code injection due to improper validation of input files. By providing a specially crafted malfeasant scan_lib.bin file, an attacker can exploit this vulnerability to execute arbitrary code within the system. This risk poses significant security threats, particularly for installations relying on the affected version, namely P3-550E 1.2.10.9, underscoring the need for immediate attention and remediation.

Affected Version(s)

P3-550E 1.2.10.9

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Matt Wiseman of Cisco Talos.
.