CVE-2024-45969
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-45969 is a newly disclosed cybersecurity vulnerability affecting the MMS Client in MZ Automation LibIEC1850. This issue permits a malicious server to trigger a Denial-of-Service condition by sending a specially crafted MMS InitiationResponse message. The vulnerability is due to a NULL pointer dereference that occurs before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 in the software. Successful exploitation of this vulnerability could lead to the crashing of the MMS Client, causing service disruptions and potential downtime for organizations using the affected software. Organizations running MZ Automation LibIEC1850 are strongly advised to apply the necessary patches to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.