CVE-2024-32850 Vulnerability Details

  /     /     /  

CVE-2024-32850 Metadata Quick Info

CVE Published: 31/05/2024 | CVE Updated: 02/08/2024 | CVE Year: 2024
Source: jpcert | Vendor: Seiko Solutions Inc. | Product: SkyBridge MB-A100/MB-A110
Status : PUBLISHED

CVE-2024-32850 Description

Improper neutralization of special elements used in a command (\'Command Injection\') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 and earlier. If the remote monitoring and control function is enabled on the product, an attacker with access to the product may execute an arbitrary command or login to the product with the administrator privilege.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Improper Neutralization of Special Elements used in a Command ( Command Injection )
Source: Seiko Solutions Inc.

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).