CVE-2024-25136

EUVD-2024-22484
There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.

Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 37%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
automationdirectc-more_ea9-t6cl_firmware
𝑥
≤ 6.77
ADP
automationdirectc-more_ea9-t7cl_firmware
𝑥
≤ 6.77
ADP
automationdirectc-more_ea9-t7cl-r_firmware
𝑥
≤ 6.77
ADP
automationdirectc-more_ea9-t8cl_firmware
𝑥
≤ 6.77
ADP
automationdirectc-more_ea9-t10cl_firmware
𝑥
≤ 6.77
ADP
automationdirectc-more_ea9-t10wcl_firmware
𝑥
≤ 6.77
ADP
automationdirectc-more_ea9-t12cl_firmware
𝑥
≤ 6.77
ADP
automationdirectc-more_ea9-t15cl_firmware
𝑥
≤ 6.77
ADP
automationdirectc-more_ea9-t15cl-r_firmware
𝑥
≤ 6.77
ADP
automationdirectc-more_ea9-rhmi_firmware
𝑥
≤ 6.77
ADP
automationdirectc-more_ea9-pgmsw_firmware
𝑥
≤ 6.77
ADP