PT-2024-24214 · Terratec · Terratec Dmx 6Fire Usb

Joseph Kwabena Fiagbor

·

Published

2024-04-23

·

Updated

2024-11-22

·

CVE-2024-31804

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Terratec DMX 6Fire USB version 1.23.0.02
Description An unquoted service path vulnerability allows a local attacker to escalate privileges via the Program.exe component.
Recommendations For Terratec DMX 6Fire USB version 1.23.0.02, consider updating to a newer version that quotes the service path to prevent privilege escalation. As a temporary workaround, restrict access to the Program.exe component to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-31804

Affected Products

Terratec Dmx 6Fire Usb