PT-2024-32906 · Device · Device

Johannes Kruchem

·

Published

2024-10-15

·

Updated

2024-10-15

·

CVE-2024-47944

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Device (affected versions not specified)
Description The issue allows for unauthenticated code execution via the firmware upgrade function. This occurs because the device directly executes .patch firmware upgrade files from a USB stick without requiring any prior authentication in the admin interface.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47944

Affected Products

Device