PT-2024-24214 · Terratec · Terratec Dmx 6Fire Usb

·

CVE-2024-31804

·

Published

2024-04-23

·

Updated

2024-11-22

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Terratec DMX 6Fire USB version 1.23.0.02
Description An unquoted service path vulnerability allows a local attacker to escalate privileges via the Program.exe component.
Recommendations For Terratec DMX 6Fire USB version 1.23.0.02, consider updating to a newer version that quotes the service path to prevent privilege escalation. As a temporary workaround, restrict access to the Program.exe component to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-31804

Affected Products

Terratec Dmx 6Fire Usb