CVE-2024-46603 Details
Description
An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.
A vulnerability allowing XML External Entity (XXE) attacks has been identified in Elspec Engineering G5 Digital Fault Recorder Firmware versions through 1.2.1.12. This vulnerability allows attackers to craft XML payloads that can cause a Denial-of-Service (DoS) condition on the device.
Users can upgrade to Elspec G5 Digital Fault Recorder Firmware version 1.2.2.19 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.elspec-ltd.com/support/security-advisories/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| elspec-ltd g5dfr firmware | < 1.2.2.19 |
CPE
Remediation
| |
| elspec-ltd g5dfr | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 16, 2025 | Initial Analysis | [email protected] |
| Jan 9, 2025 | CVE Modified | [email protected] |
| Jan 7, 2025 | CVE Modified | CISA-ADP |
| Jan 7, 2025 | New CVE Received | [email protected] |