CVE-2024-25088: High severity jungo windriver vulnerability
Published Jul 2, 2024
·Updated
Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.
Affected Software
43 affected components
Jungo Windriver<12.5.1
Mitsubishielectric Cpu Module Logging Configuration Tool
Mitsubishielectric Cw Configurator
Mitsubishielectric Data Transfer
Mitsubishielectric Data Transfer Classic
Mitsubishielectric Ezsocket
Mitsubishielectric Fr Configurator Sw3
Mitsubishielectric Fr Configurator2
Mitsubishielectric Genesis64
Mitsubishielectric Gt Got1000
Mitsubishielectric Gt Got2000
Mitsubishielectric Gt Softgot1000
Mitsubishielectric Gt Softgot2000
Mitsubishielectric Gx Developer
Mitsubishielectric Gx Logviewer
Mitsubishielectric Gx Works2
Mitsubishielectric Gx Works3
Mitsubishielectric Iq Works
Mitsubishielectric Mi Configurator
Mitsubishielectric Mr Configurator
Mitsubishielectric Mr Configurator2
Mitsubishielectric Mx Component
Mitsubishielectric Mx Opc Server Da\/ua
Mitsubishielectric Numerical Control Device Communication
Mitsubishielectric Px Developer\/monitor Tool
Mitsubishielectric Rt Toolbox3
Mitsubishielectric Rt Visualbox
All of the following
Mitsubishielectric Mrzjw3-mc2-utl Firmware
Mitsubishielectric Mrzjw3-mc2-utl
All of the following
Mitsubishielectric Sw0dnc-mneth-b Firmware
Mitsubishielectric Sw0dnc-mneth-b
All of the following
Mitsubishielectric Sw1dnc-ccbd2-b Firmware
Mitsubishielectric Sw1dnc-ccbd2-b
All of the following
Mitsubishielectric Sw1dnc-ccief-j Firmware
Mitsubishielectric Sw1dnc-ccief-j
All of the following
Mitsubishielectric Sw1dnc-ccief-b Firmware
Mitsubishielectric Sw1dnc-ccief-b
All of the following
Mitsubishielectric Sw1dnc-mnetg-b Firmware
Mitsubishielectric Sw1dnc-mnetg-b
All of the following
Mitsubishielectric Sw1dnc-qsccf-b Firmware
Mitsubishielectric Sw1dnc-qsccf-b
All of the following
Mitsubishielectric Sw1dnd-emsdk-b Firmware
Mitsubishielectric Sw1dnd-emsdk-b
Event History
Jul 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-25088?
CVE-2024-25088 has a critical severity level due to its potential for local privilege escalation and arbitrary code execution.
2
How do I fix CVE-2024-25088?
To fix CVE-2024-25088, update Jungo WinDriver to version 12.5.1 or later.
3
Which software is affected by CVE-2024-25088?
CVE-2024-25088 affects various software products including Jungo WinDriver and multiple Mitsubishi Electric tools.
4
What kind of attack does CVE-2024-25088 facilitate?
CVE-2024-25088 allows local attackers to escalate their privileges and execute arbitrary code on the affected systems.
5
When was CVE-2024-25088 disclosed?
CVE-2024-25088 was disclosed in 2024, highlighting significant security concerns in the affected software versions.