CVE-2024-50960: Command Injection
A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50960?
CVE-2024-50960 is categorized as a high-severity command injection vulnerability.
How do I fix CVE-2024-50960?
To remediate CVE-2024-50960, update the Extron SMP 111 to version 3.02 or later, and SMP 351 and SMP 352 to version 2.17 or later.
Who is affected by CVE-2024-50960?
CVE-2024-50960 affects Extron SMP 111 versions up to 3.01, and SMP 351 and SMP 352 versions up to 2.16.
What type of vulnerability is CVE-2024-50960?
CVE-2024-50960 is a command injection vulnerability that allows remote authenticated attackers to execute arbitrary commands.
Can CVE-2024-50960 be exploited remotely?
Yes, CVE-2024-50960 can be exploited remotely by authenticated attackers with administrative privileges.