Out-of-bounds Write Vulnerabilities in AutomationDirect P3-550E Firmware
CVE-2024-24959

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
28 May 2024

What is CVE-2024-24959?

Multiple out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of the AutomationDirect P3-550E firmware version 1.2.10.9. These vulnerabilities may be exploited by sending specially crafted network packets, resulting in potential heap-based memory corruption. The issue specifically involves an arbitrary null-byte write vulnerability located at offset 0xb6c18 in the firmware code. This flaw can be leveraged by attackers to disrupt the software's operation or execute arbitrary code, highlighting significant risks for users of the affected product.

Affected Version(s)

P3-550E 1.2.10.9

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Matt Wiseman of Cisco Talos.
.