Out-of-bounds Write Vulnerabilities in AutomationDirect P3-550E Firmware
CVE-2024-24958

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
28 May 2024

What is CVE-2024-24958?

The AutomationDirect P3-550E Programming Software exhibits several out-of-bounds write vulnerabilities within its FileSystem API functionality. These vulnerabilities arise from improperly handled network packets, which can lead to heap-based memory corruption. By sending specially crafted malicious packets, an attacker may exploit these vulnerabilities to manipulate the device's memory. This particular issue has been tracked due to an arbitrary null-byte write vulnerability found in firmware version 1.2.10.9, located at offset 0xb6bdc, emphasizing the need for immediate attention to system security measures.

Affected Version(s)

P3-550E 1.2.10.9

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Matt Wiseman of Cisco Talos.
.