CVE-2024-53542 Details
Description
Incorrect access control in the component /iclock/Settings?restartNCS=1 of NovaCHRON Zeitsysteme GmbH & Co. KG Smart Time Plus v8.x to v8.6 allows attackers to arbitrarily restart the NCServiceManger via a crafted GET request.
A vulnerability exists in NovaCHRON Smart Time Plus versions 8.x prior to 8.6, specifically in the web component accessed through the '/iclock/Settings?restartNCS=1' endpoint. This vulnerability allows attackers to bypass access controls and arbitrarily restart the NCServiceManager on the host via a crafted GET request. The NCServiceManager runs as a Windows service under the SYSTEM account, and while the service restart itself does not have a significant impact, it can be exploited to cause a denial-of-service condition by repeatedly restarting the service, causing the web application to become unavailable.
Users should update to NovaCHRON Smart Time Plus version 8.6 or later, ensuring that the latest 8.6 installation package is used. The version 8.6.1.01 Build 1017 is confirmed to contain the necessary fixes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 24, 2025CISA-ADP
Assessed Feb 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://secure77.de/smart-time-plus-rce-cve-2024-53543/ | [email protected] | BundleExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| NovaCHRON Smart Time Plus | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 25, 2025 | CVE Modified | CISA-ADP |
| Feb 24, 2025 | New CVE Received | [email protected] |
Volerion