PT-2024-3884 · Automationdirect · P3-550E

Matt Wiseman

·

Published

2024-05-23

·

Updated

2025-02-12

·

CVE-2024-24956

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:P/A:C
Name of the Vulnerable Software and Affected Versions: AutomationDirect P3-550E version 1.2.10.9
Description: The issue is related to out-of-bounds write vulnerabilities in the Programming Software Connection FileSystem API functionality. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities, potentially causing a denial of service. The arbitrary null-byte write vulnerability is located at offset 0xb6a38 in firmware 1.2.10.9 of the P3-550E.
Recommendations: For AutomationDirect P3-550E version 1.2.10.9, consider disabling the FileSystem API functionality until a patch is available to prevent exploitation of the out-of-bounds write vulnerabilities. Restrict access to the Programming Software Connection to minimize the risk of malicious packet delivery. Avoid using the offset 0xb6a38 in the affected firmware until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-04288
CVE-2024-24956

Affected Products

P3-550E