CVE-2024-24947: Buffer Overflow
A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger these vulnerability.This CVE tracks the heap corruption that occurs at offset 0xb68c4 of version 1.2.10.9 of the P3-550E firmware, which occurs when a call to memset relies on an attacker-controlled length value and corrupts any trailing heap allocations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24947?
CVE-2024-24947 is a high severity vulnerability that can lead to a denial of service due to a heap-based buffer overflow.
How do I fix CVE-2024-24947?
To fix CVE-2024-24947, update your affected AutomationDirect P3-550E firmware to the latest version that mitigates this vulnerability.
What software is affected by CVE-2024-24947?
CVE-2024-24947 affects AutomationDirect P3-550E firmware versions 1.2.10.9 and 4.1.1.10.
Can an attacker exploit CVE-2024-24947 remotely?
Yes, an attacker can exploit CVE-2024-24947 by sending a specially crafted unauthenticated network packet.
What symptoms indicate an exploitation of CVE-2024-24947?
Indicators of exploitation of CVE-2024-24947 may include unexpected crashes or denial of service in affected systems.