PT-2024-5282 · Automationdirect · Automationdirect P3-550E

Matt Wiseman

·

Published

2024-05-28

·

Updated

2024-06-10

·

CVE-2024-23601

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AutomationDirect P3-550E version 1.2.10.9
Description The issue is related to insufficient data authentication in the scan lib.bin library of the AutomationDirect P3-550E programmable logic controller's software. This can allow a remote attacker to execute arbitrary code or cause a denial of service by exploiting the vulnerability. A specially crafted scan lib.bin file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Recommendations For AutomationDirect P3-550E version 1.2.10.9, consider disabling the scan lib.bin functionality until a patch is available to prevent arbitrary code execution. Restrict access to the scan lib.bin file to minimize the risk of exploitation. Avoid using malicious or unverified scan lib.bin files to prevent triggering the vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Verification of Data Authenticity

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05901
CVE-2024-23601

Affected Products

Automationdirect P3-550E