Bypass Secure Update Vulnerability in RTU500
CVE-2024-2617
7.2HIGH
Summary
A vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update. If a malicious actor successfully exploits this vulnerability, they could use it to update the RTU500 with unsigned firmware.
Affected Version(s)
RTU500 series CMU firmware <= 13.2.7
RTU500 series CMU firmware <= 13.4.4
RTU500 series CMU firmware <= 13.5.3
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database