CVE-2024-46602

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 7, 2025
Updated: Jan 9, 2025
CWE ID 611

Summary

CVE-2024-46602 is an XML External Entity (XXE) vulnerability affecting Elspec G5 digital fault recorders version 1.2.1.12 and earlier. An attacker can exploit this issue by sending a maliciously crafted XML payload, potentially triggering a Denial of Service (DoS) condition. The vulnerability may allow unintended data access or system crashes, posing a significant security risk. Elspec urges users to update their software to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share