CVE-2024-24962 Details
Description
A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacker can send an unauthenticated packet to trigger this vulnerability.This CVE tracks the stack-based buffer overflow that occurs at offset `0xb6e98` of v1.2.10.9 of the P3-550E firmware.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2024-1939 | CVE | ExploitThird Party Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1939 | CVE | ExploitThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2024-1939 | [email protected] | ExploitThird Party Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1939 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| automationdirect p3-550e firmware | 1.2.10.9 4.1.1.10 |
CPE
Remediation
| |
| automationdirect p3-550e | All versions |
CPE
Remediation
| |
| automationdirect p3-550 firmware | 1.2.10.9 4.1.1.10 |
CPE
Remediation
| |
| automationdirect p3-550 | All versions |
CPE
Remediation
| |
| automationdirect p3-530 firmware | 1.2.10.9 4.1.1.10 |
CPE
Remediation
| |
| automationdirect p3-530 | All versions |
CPE
Remediation
| |
| automationdirect p2-550 firmware | 1.2.10.10 4.1.1.10 |
CPE
Remediation
| |
| automationdirect p2-550 | All versions |
CPE
Remediation
| |
| automationdirect p1-550 firmware | 1.2.10.10 4.1.1.10 |
CPE
Remediation
| |
| automationdirect p1-550 | All versions |
CPE
Remediation
| |
| automationdirect p1-540 firmware | 1.2.10.10 4.1.1.10 |
CPE
Remediation
| |
| automationdirect p1-540 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 10, 2024 | CVE Modified | [email protected] |
| May 28, 2024 | New CVE Received | [email protected] |