CVE-2024-25136: AutomationDirect C-MORE EA9 HMI Path Traversal
Published Mar 26, 2024
·Updated
There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.
Affected Software
1 affected component
AutomationDirect C-MORE EA9 HMI
Remediation
Information
AutomationDirect recommends that users update C-MORE EA9 HMI to V6.78 https://www.automationdirect.com/support/software-downloads .
Event History
Mar 26, 2024
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-25136?
CVE-2024-25136 is considered a high-severity vulnerability due to improper input sanitization.
2
How do I fix CVE-2024-25136?
To fix CVE-2024-25136, ensure that all URL inputs are properly sanitized and validated before processing.
3
What systems are affected by CVE-2024-25136?
CVE-2024-25136 specifically affects the AutomationDirect C-MORE EA9 HMI.
4
What kind of attacks can be executed using CVE-2024-25136?
An attacker can exploit CVE-2024-25136 to perform directory traversal attacks by sending maliciously crafted URLs.
5
Is there a patch available for CVE-2024-25136?
As of now, it's recommended to check with AutomationDirect for any available patches or updates addressing CVE-2024-25136.