CVE-2024-12442 Details
Description
EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.
A command injection vulnerability has been identified in EnerSys AMPA versions 24.04 through 24.16, inclusive. This vulnerability allows for privileged remote shell access. The issue arises on the Network Diagnostics webpage of Alpha XM3.1 and Alpha Gateway devices, enabling unauthenticated remote code execution.
Users are advised to upgrade to EnerSys AMPA version 24.17. For Alpha XM3.1 Broadband UPS, upgrade to version 1.10.01 or later. For Alpha Gateway Firmware, upgrade to version 2.07.01 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 9, 2025CISA-ADP
Assessed May 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2025/MNDT-2025-0002.md | [email protected] | AdvisoryBundleRemedy |
| https://www.enersys.com/4996df/globalassets/documents/corporate/cve/enersys_cve-2024-12442-final.pdf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| EnerSys AMPA | All versions |
CPE
Remediation
| |
| EnerSys Alpha XM3.1 | >= 1.10.00, < 1.10.01 (semver) |
CPE
Remediation
| |
| EnerSys Alpha Gateway | >= 2.07.00, < 2.07.01 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2025 | CVE Modified | CISA-ADP |
| May 9, 2025 | New CVE Received | [email protected] |
Volerion