Out-of-bounds Write Vulnerabilities in AutomationDirect P3-550E Firmware
CVE-2024-24959
8.2HIGH
What is CVE-2024-24959?
Multiple out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of the AutomationDirect P3-550E firmware version 1.2.10.9. These vulnerabilities may be exploited by sending specially crafted network packets, resulting in potential heap-based memory corruption. The issue specifically involves an arbitrary null-byte write vulnerability located at offset 0xb6c18
in the firmware code. This flaw can be leveraged by attackers to disrupt the software's operation or execute arbitrary code, highlighting significant risks for users of the affected product.
Affected Version(s)
P3-550E 1.2.10.9
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Matt Wiseman of Cisco Talos.