Out-of-bounds Write Vulnerabilities in AutomationDirect P3-550E Firmware
CVE-2024-24956

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
28 May 2024

What is CVE-2024-24956?

Multiple out-of-bounds write vulnerabilities have been identified in the Programming Software Connection FileSystem API of AutomationDirect's P3-550E model, specifically in firmware version 1.2.10.9. These vulnerabilities arise from the ability of an attacker to send specially crafted network packets, which can trigger heap-based memory corruption. One such vulnerability allows for an arbitrary null-byte write at a specific offset, posing significant security risks. As attackers leverage these vulnerabilities, they can potentially execute unauthorized operations or disrupt the normal functioning of the affected firmware. It is crucial for users to remain informed about these vulnerabilities and apply recommended security practices to mitigate the associated risks.

Affected Version(s)

P3-550E 1.2.10.9

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Matt Wiseman of Cisco Talos.
.