PT-2024-5282 · Automationdirect · Automationdirect P3-550E
Matt Wiseman
·
Published
2024-05-28
·
Updated
2024-06-10
·
CVE-2024-23601
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AutomationDirect P3-550E version 1.2.10.9
Description
The issue is related to insufficient data authentication in the scan lib.bin library of the AutomationDirect P3-550E programmable logic controller's software. This can allow a remote attacker to execute arbitrary code or cause a denial of service by exploiting the vulnerability. A specially crafted scan lib.bin file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Recommendations
For AutomationDirect P3-550E version 1.2.10.9, consider disabling the scan lib.bin functionality until a patch is available to prevent arbitrary code execution. Restrict access to the scan lib.bin file to minimize the risk of exploitation. Avoid using malicious or unverified scan lib.bin files to prevent triggering the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficient Verification of Data Authenticity
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Automationdirect P3-550E