- Description
- Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network access and the user level ”Service”, an attacker can execute arbitrary system commands in the root user’s contexts.
- Source
- psirt@sick.de
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- psirt@sick.de
- CWE-94
- Hype score
- Not currently trending
CVE-2024-10771 (CVSS:8.8, HIGH) is Awaiting Analysis. Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code..https://t.co/SzHYIz6xHq #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
11 Dec 2024
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2024-10771 Due to missing input validation during one step of the firmware update process, the product is vulnerable to remote code execution. With network access and the user l… https://t.co/Qkitj9q2xw
@CVEnew
6 Dec 2024
263 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[CVE-2024-10771: HIGH] Product vulnerable to remote code execution due to missing input validation in firmware update process. Attacker with network access can execute system commands as root.#cybersecurity,#vulnerability https://t.co/0DdSzATZS3 https://t.co/FC50rnQ7lF
@CveFindCom
6 Dec 2024
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes