CVE-2024-11999

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Dec 17, 2024
CWE ID 1104

Summary

CVE-2024-11999 is a newly identified vulnerability labeled as CWE-1104: Use of Unmaintained Third-Party Components. This issue puts devices at risk, allowing an authenticated user to gain complete control by installing malicious code into an HMI product. The vulnerability arises due to the use of outdated or unsupported third-party components, which may contain weaknesses that attackers can exploit. The precise nature of the exploit and the affected devices have yet to be disclosed. Users are strongly advised to keep their systems updated and secure, and to exercise caution when installing third-party components.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share