CVE-2024-8938

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Nov 13, 2024
CWE ID 119

Summary

CVE-2024-8938 is a newly disclosed vulnerability identified as CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer. This issue puts systems at risk of arbitrary code execution, following a successful Man-In-The-Middle (MITM) attack. The attacker can manipulate a crafted Modbus function call to tamper with the memory area involved in memory size computation, allowing the execution of unauthorized code. By exploiting this vulnerability, an adversary can potentially gain unlimited access and control over the targeted system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share