CVE-2024-24946: Buffer Overflow
A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger these vulnerability.This CVE tracks the heap corruption that occurs at offset 0xb686c of version 1.2.10.9 of the P3-550E firmware, which occurs when a call to memset relies on an attacker-controlled length value and corrupts any trailing heap allocations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24946?
CVE-2024-24946 is identified as a heap-based buffer overflow vulnerability that can lead to denial of service.
How do I fix CVE-2024-24946?
To fix CVE-2024-24946, ensure to apply the latest firmware updates provided by AutomationDirect for affected products.
Which products are affected by CVE-2024-24946?
CVE-2024-24946 affects AutomationDirect P3-550E and other related models running specific firmware versions.
Can CVE-2024-24946 be exploited remotely?
Yes, CVE-2024-24946 can be exploited by sending specially crafted unauthenticated network packets from remote locations.
What is a potential impact of CVE-2024-24946?
The potential impact of CVE-2024-24946 includes denial of service, disrupting normal operations of the affected devices.