PT-2024-34470 · Xinje · Xinje Xl5E-16T+1

Published

2024-11-13

·

Updated

2024-11-15

·

CVE-2024-50955

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: XINJE XD5E-24R version 3.5.3b XINJE XL5E-16T version 3.5.3b
Description: An issue in how XINJE controllers handle TCP protocol messages allows attackers to cause a Denial of Service (DoS) via a crafted TCP message.
Recommendations: For XINJE XD5E-24R version 3.5.3b, consider disabling TCP protocol message handling until a patch is available. For XINJE XL5E-16T version 3.5.3b, restrict access to the TCP protocol to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2024-50955

Affected Products

Xinje Xd5E-24R
Xinje Xl5E-16T