CVE-2024-10776
CVSS V2 None
CVSS V3 None
Description
Lua apps can be deployed, removed, started, reloaded or stopped without authorization via
AppManager. This allows an attacker to remove legitimate apps creating a DoS attack, read and write
files or load apps that use all features of the product available to a customer.
Overview
- CVE ID
- CVE-2024-10776
- Assigner
- SICK AG
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-12-06T12:38:55.781Z
- Last Modified Date
- 2024-12-06T18:52:27.865Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://sick.com/psirt | x_SICK PSIRT Website |
https://cdn.sick.com/media/docs/1/11/411/Special_information_CYBERSECURITY_BY_SICK_en_IM0084411.PDF | x_SICK Operating Guidelines |
https://www.cisa.gov/resources-tools/resources/ics-recommended-practices | x_ICS-CERT recommended practices on Industrial Security |
https://www.first.org/cvss/calculator/3.1 | x_CVSS v3.1 Calculator |
https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.pdf | vendor-advisory |
https://www.sick.com/.well-known/csaf/white/2024/sca-2024-0006.json | vendor-advisory x_csaf |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-10776 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-10776 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-12-07 13:13:57 | Added to TrackCVE |