CVE Published: 15/10/2024 |
CVE Updated: 15/10/2024 |
CVE Year: 2024 Source: SEC-VLab |
Vendor: RITTAL GmbH & Co. KG |
Product: IoT Interface & CMC III Processing Unit Status : PUBLISHED
CVE-2024-47944 Description
The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated code execution via the firmware upgrade function.