CVE-2024-11013: Command Injection
Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11013?
CVE-2024-11013 is classified as a high severity command injection vulnerability.
How do I fix CVE-2024-11013?
To fix CVE-2024-11013, update your NEC UNIVERGE IX software to the latest versions above 10.10.21, 10.8.27, 10.9.14, or ensure UNIVERGE IX-R/IX-V versions are above 1.2.15.
What devices are affected by CVE-2024-11013?
CVE-2024-11013 affects NEC UNIVERGE IX versions from 9.2 to 10.10.21, and specifically versions up to 10.8.27 and 10.9.14, as well as UNIVERGE IX-R/IX-V up to version 1.2.15.
What types of attacks can result from CVE-2024-11013?
CVE-2024-11013 can allow attackers to execute arbitrary command line interface commands on vulnerable NEC devices.
How can I determine if my NEC device is vulnerable to CVE-2024-11013?
Check your NEC UNIVERGE IX or IX-R/IX-V device version against the affected versions listed in CVE-2024-11013 to see if it is vulnerable.