CVE-2024-23315: High severity automationdirect p3-550e firmware vulnerability
A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can send an unauthenticated packet to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23315?
CVE-2024-23315 is classified as a read-what-where vulnerability that can lead to the disclosure of sensitive information.
How do I fix CVE-2024-23315?
To address CVE-2024-23315, it is recommended to apply the latest firmware updates provided by AutomationDirect for affected products.
Which products are affected by CVE-2024-23315?
CVE-2024-23315 affects AutomationDirect P3-550E, P3-550, P3-530, P2-550, P1-550, P1-540 firmware versions 1.2.10.9 and 4.1.1.10.
Can CVE-2024-23315 be exploited remotely?
Yes, CVE-2024-23315 can be exploited remotely by sending a specially crafted unauthenticated network packet.
What kind of data can be exposed due to CVE-2024-23315?
Exploitation of CVE-2024-23315 may lead to the disclosure of sensitive information stored in the affected devices.