PT-2024-31413 · Unknown · Progauge Maglink Lx Console

Pedro Umbelino

·

Published

2024-09-24

·

Updated

2024-11-07

·

CVE-2024-45066

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ProGauge MAGLINK LX CONSOLE (affected versions not specified)
Description A specially crafted POST request to the "ProGauge MAGLINK LX CONSOLE IP sub-menu" can allow a remote attacker to inject arbitrary commands. This issue is being actively exploited. The vulnerability affects Automated Tank Gauge (ATG) systems, which are crucial for managing fuel storage tanks in critical infrastructure sectors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-45066

Affected Products

Progauge Maglink Lx Console