CVE-2024-1015

CRITICAL

SE-elektronic E-DDC3.3 Firmware 03.07.03 and higher - Remote Code Execution via Web Configuration

Title source: llm
STIX 2.1

Description

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.

Scores

CVSS v3 9.8
EPSS 0.0145
EPSS Percentile 70.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
se-elektronic/e-ddc3.3_firmware 03.07.03
Published Jan 29, 2024
Tracked Since Feb 18, 2026