CVE-2024-22081

CRITICAL

Espec G5 <1.1.4.15 - Memory Corruption

Title source: llm
STIX 2.1

Description

An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Unauthenticated memory corruption can occur in the HTTP header parsing mechanism.

Scores

CVSS v3 9.8
EPSS 0.0037
EPSS Percentile 59.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-444
Status published
Products (1)
elspec-ltd/g5dfr_firmware < 1.2.1.12
Published Mar 20, 2024
Tracked Since Feb 18, 2026