Out-of-bounds Write Vulnerabilities in AutomationDirect P3-550E Firmware
CVE-2024-24958
8.2HIGH
What is CVE-2024-24958?
The AutomationDirect P3-550E Programming Software exhibits several out-of-bounds write vulnerabilities within its FileSystem API functionality. These vulnerabilities arise from improperly handled network packets, which can lead to heap-based memory corruption. By sending specially crafted malicious packets, an attacker may exploit these vulnerabilities to manipulate the device's memory. This particular issue has been tracked due to an arbitrary null-byte write vulnerability found in firmware version 1.2.10.9, located at offset 0xb6bdc
, emphasizing the need for immediate attention to system security measures.
Affected Version(s)
P3-550E 1.2.10.9
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Matt Wiseman of Cisco Talos.