Out-of-bounds Write Vulnerabilities in AutomationDirect P3-550E Firmware
CVE-2024-24956
What is CVE-2024-24956?
Multiple out-of-bounds write vulnerabilities have been identified in the Programming Software Connection FileSystem API of AutomationDirect's P3-550E model, specifically in firmware version 1.2.10.9. These vulnerabilities arise from the ability of an attacker to send specially crafted network packets, which can trigger heap-based memory corruption. One such vulnerability allows for an arbitrary null-byte write at a specific offset, posing significant security risks. As attackers leverage these vulnerabilities, they can potentially execute unauthorized operations or disrupt the normal functioning of the affected firmware. It is crucial for users to remain informed about these vulnerabilities and apply recommended security practices to mitigate the associated risks.
Affected Version(s)
P3-550E 1.2.10.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved