Arbitrary Code Execution Vulnerability in AutomationDirect P3-550E 1.2.10.9 Due to Code Injection
CVE-2024-23601
9.8CRITICAL
What is CVE-2024-23601?
A vulnerability exists within the scan_lib.bin functionality of AutomationDirect's P3-550E, which allows for code injection due to improper validation of input files. By providing a specially crafted malfeasant scan_lib.bin file, an attacker can exploit this vulnerability to execute arbitrary code within the system. This risk poses significant security threats, particularly for installations relying on the affected version, namely P3-550E 1.2.10.9, underscoring the need for immediate attention and remediation.
Affected Version(s)
P3-550E 1.2.10.9
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Matt Wiseman of Cisco Talos.