CVE-2024-23601
28.05.2024, 16:15
A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Vendor | Product | Version |
---|---|---|
automationdirect | p3-550e_firmware | 1.2.10.9 |
automationdirect | p3-550e_firmware | 4.1.1.10 |
automationdirect | p3-550_firmware | 1.2.10.9 |
automationdirect | p3-550_firmware | 4.1.1.10 |
automationdirect | p3-530_firmware | 1.2.10.9 |
automationdirect | p3-530_firmware | 4.1.1.10 |
automationdirect | p2-550_firmware | 1.2.10.10 |
automationdirect | p2-550_firmware | 4.1.1.10 |
automationdirect | p1-550_firmware | 1.2.10.10 |
automationdirect | p1-550_firmware | 4.1.1.10 |
automationdirect | p1-540_firmware | 1.2.10.10 |
automationdirect | p1-540_firmware | 4.1.1.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-345 - Insufficient Verification of Data AuthenticityThe software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
- CWE-94 - Improper Control of Generation of Code ('Code Injection')The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
References