CVE-2024-46603
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-46603 is an XML External Entity (XXE) vulnerability affecting Elspec Engineering's G5 Digital Fault Recorder Firmware version 1.2.1.12. This issue allows attackers to trigger a Denial of Service (DoS) condition by delivering a crafted XML payload. The XML parser in the firmware fails to properly validate and sanitize XML input, leading to the vulnerability. Attackers can exploit this to cause the system to become unresponsive or halt its operations, resulting in a disruption of services. Users of the affected firmware are urged to apply the necessary patches or upgrades to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.