Record summary

CVE-2024-27121 has a selected CVSS score of 7.2 (high).

Description

Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege. As for the details of the affected product names/versions, see the information provided by the vendor under [References] section.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2024 · Source: CVE List

Affected products and versions

5
ProductSourceVersion rangeStatus
CVE ListNJ101-[][][][] Ver.1.64.03 and earlieraffected
NJ301-[][][][] Ver.1.64.00 and earlieraffected
NJ501-1[]0[] Ver.1.64.03 and earlieraffected
NJ501-1[]2[] Ver.1.64.00 and earlieraffected
NJ501-1340 Ver.1.64.00 and earlieraffected
NJ501-4[][][] Ver.1.64.00 and earlieraffected
NJ501-5300 Ver.1.64.00 and earlieraffected
NJ501-R[][][] Ver.1.64.00 and earlieraffected
CVE ListNX102-[][][][] Ver.1.64.00 and earlieraffected
NX502-[][][][] Ver.1.65.01 and earlieraffected
NX701-[][][][] Ver.1.35.00 and earlieraffected
NX-EIP201 Ver.1.00.01 and earlieraffected
NX1P2-[][][][][][] Ver.1.64.00 and earlieraffected
NX1P2-[][][][][][]1 Ver.1.64.00 and earlieraffected

Default status: unknown

CVE ListThrough 1.64.03affected

Default status: unknown

CVE ListThrough 1.64.00affected

Default status: unknown

CVE ListThrough 1.64.00affected

References

4