CVE-2024-28878

CRITICAL

IO-1020 Micro ELD - Code Injection

Title source: llm
STIX 2.1

Description

IO-1020 Micro ELD downloads source code or an executable from an adjacent location and executes the code without sufficiently verifying the origin or integrity of the code.

Scores

CVSS v3 9.6
EPSS 0.0007
EPSS Percentile 21.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-494
Status published
Products (1)
IOSiX/IO-1020 Micro ELD < 360
Published Apr 12, 2024
Tracked Since Feb 18, 2026