PT-2024-16531 · Sick Ag+1 · Sick Inspectorp61X+4

Manuel Stotz

+2

·

Published

2024-12-06

·

Updated

2024-12-11

·

CVE-2024-10771

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Product (affected versions not specified)
Description The product is vulnerable to remote code execution due to missing input validation during one step of the firmware update process. An attacker with network access and the user level "Service" can execute arbitrary system commands in the root user's context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-10771

Affected Products

Sick Inspectorp61X
Sick Inspectorp62X
Tim3Xx
Inspector61X Firmware
Inspector62X Firmware