Peak System · Pcan-Ethernet Gateway · CVE-2024-44610
**Name of the Vulnerable Software and Affected Versions**
PCAN-Ethernet Gateway FD versions prior to 1.3.0
PCAN-Ethernet Gateway versions prior to 2.11.0
**Description**
The issue is related to Command injection via shell metacharacters in a Software Update to `processing.php`. This allows for potential command injection attacks.
**Recommendations**
For PCAN-Ethernet Gateway FD versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue.
For PCAN-Ethernet Gateway versions prior to 2.11.0, update to version 2.11.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the `processing.php` file until a patch is available.