CVE-2024-54089

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 11, 2025
CWE ID 326

Summary

CVE-2024-54089 is a newly identified vulnerability affecting various models of APOGEE PXC Series (BACnet) and TALON TC Series (BACnet) devices, as well as their P2 Ethernet versions. The issue stems from a weak encryption mechanism utilizing a hard-coded key. An attacker can exploit this flaw to decrypt the password from the cyphertext, potentially gaining unauthorized access to the affected devices. This vulnerability poses a significant risk to security, and it is recommended that affected organizations apply the necessary patches or upgrades as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share