PT-2024-19572 · Tormach · Pathpilot Controller+1

Irfan Ahmed

+1

·

Published

2024-04-22

·

Updated

2025-09-15

·

CVE-2024-22811

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tormach xsTECH CNC Router, PathPilot Controller version 2.9.6
Description The issue allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the Hostmot2 configuration cookie in the device memory.
Recommendations For version 2.9.6, consider restricting access to the device memory to prevent overwriting of the Hostmot2 configuration cookie until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2024-22811

Affected Products

Pathpilot Controller
Tormach Xstech Cnc Router