CVE-2024-25136
EUVD-2024-2248426.03.2024, 23:15
There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| automationdirect | c-more_ea9-t6cl_firmware | 𝑥 ≤ 6.77 | ADP |
| automationdirect | c-more_ea9-t7cl_firmware | 𝑥 ≤ 6.77 | ADP |
| automationdirect | c-more_ea9-t7cl-r_firmware | 𝑥 ≤ 6.77 | ADP |
| automationdirect | c-more_ea9-t8cl_firmware | 𝑥 ≤ 6.77 | ADP |
| automationdirect | c-more_ea9-t10cl_firmware | 𝑥 ≤ 6.77 | ADP |
| automationdirect | c-more_ea9-t10wcl_firmware | 𝑥 ≤ 6.77 | ADP |
| automationdirect | c-more_ea9-t12cl_firmware | 𝑥 ≤ 6.77 | ADP |
| automationdirect | c-more_ea9-t15cl_firmware | 𝑥 ≤ 6.77 | ADP |
| automationdirect | c-more_ea9-t15cl-r_firmware | 𝑥 ≤ 6.77 | ADP |
| automationdirect | c-more_ea9-rhmi_firmware | 𝑥 ≤ 6.77 | ADP |
| automationdirect | c-more_ea9-pgmsw_firmware | 𝑥 ≤ 6.77 | ADP |