CVE-2024-50954

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 15, 2025
Updated: Jan 17, 2025
CWE ID 94

Summary

CVE-2024-50954 is a vulnerability affecting the XINJE XL5E-16T and XD5E-24R-E programmable logic controllers (PLCs) with versions V3.5.3b to V3.7.2a. This issue arises from the controllers' handling of Modbus messages. A successful exploit involves establishing a TCP connection on a LAN and sending a specific Modbus message to the controller, resulting in the PLC crashing. The consequences of this vulnerability include the ERR indicator light being activated and the RUN indicator light being deactivated, halting the normal operation of the programs running on the affected PLCs.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share