CVE-2024-11610
CVSS 3.0 Score 7.8 of 10 (high)
Details
Published Jan 30, 2025
CWE ID 119
Summary
CVE-2024-11610 is a remote code execution vulnerability affecting AutomationDirect C-More EA9 and EAP9 devices. The flaw arises from insufficient validation of user-supplied data during EAP9 file parsing, leading to a memory corruption condition. An attacker can exploit this vulnerability by tricking the target into visiting a malicious page or opening a specially crafted file, enabling arbitrary code execution in the context of the current process. This issue, identified as ZDI-CAN-24773, poses a significant risk to affected installations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share