CVE-2024-47943
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Oct 15, 2024
Updated: Mar 17, 2025
CWE ID 347
Summary
CVE-2024-47943 is a vulnerability affecting the firmware upgrade function in Rittal IoT Interface & CMC III Processing Unit devices. The issue lies in the way these devices verify the authenticity of patch files before executing the run.sh script. Instead of using secure signing methods, the devices rely on an HMAC with a hard-coded, publicly accessible key. This weakness allows attackers to craft malicious "signed" .patch files, enabling the execution of arbitrary code on compromised devices.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.