Out-of-bounds Write Vulnerabilities in AutomationDirect P3-550E Firmware
CVE-2024-24959
8.2HIGH
What is CVE-2024-24959?
Multiple out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of the AutomationDirect P3-550E firmware version 1.2.10.9. These vulnerabilities may be exploited by sending specially crafted network packets, resulting in potential heap-based memory corruption. The issue specifically involves an arbitrary null-byte write vulnerability located at offset 0xb6c18
in the firmware code. This flaw can be leveraged by attackers to disrupt the software's operation or execute arbitrary code, highlighting significant risks for users of the affected product.
Affected Version(s)
P3-550E 1.2.10.9