CVE-2024-45066

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP 
sub-menu can allow a remote attacker to inject arbitrary commands.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
icscertCNA
10 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
doverfuelingsolutionsprogauge_maglink_lx_console_firmware
𝑥
≤ 3.4.2.2.6
doverfuelingsolutionsprogauge_maglink_lx4_console_firmware
𝑥
≤ 4.17.9e
𝑥
= Vulnerable software versions