Heap-Based Buffer Overflow Vulnerability in AutomationDirect P3-550E 1.2.10.9
CVE-2024-24851

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
28 May 2024

What is CVE-2024-24851?

A significant heap-based buffer overflow vulnerability has been identified in the Programming Software Connection FiBurn functionality of AutomationDirect's P3-550E version 1.2.10.9. This vulnerability can be triggered remotely through the transmission of specially crafted network packets. An unauthorized attacker can exploit this weakness to execute arbitrary code, compromising system integrity and potentially leading to unauthorized access. Organizations utilizing this programming software should take immediate steps to assess and mitigate the risk presented by this vulnerability.

Affected Version(s)

P3-550E 1.2.10.9

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Matt Wiseman of Cisco Talos.
.
CVE-2024-24851 : Heap-Based Buffer Overflow Vulnerability in AutomationDirect P3-550E 1.2.10.9