jvn.jp
https://jvn.jp/en/jp/JVN46615026 CVE-2024-52564
HIGH
UD-LT1 and UD-LT1/EX Firmware Arbitrary OS Command Execution
Record summary
CVE-2024-52564 has a selected CVSS score of 7.5 (high).
Description
Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and earlier. A remote attacker may disable the firewall function of the affected products. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 4, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 6, 2024 · Source: CVE List
Affected products and versions
5| Product | Source | Version range | Status |
|---|---|---|---|
UD-LT1 and UD-LT1/EXBrowse I-O DATA DEVICE, INC / UD-LT1 and UD-LT1/EX | VulnCheck | Version data not supplied | |
| CVE List | firmware Ver.2.1.8 and earlier | affected | |
| CVE List | firmware Ver.2.1.8 and earlier | affected | |
ud-lt1\/ex_firmwareBrowse iodata / ud-lt1\/ex_firmwareDefault status: unknown | CVE List | Through 2.1.8 | affected |
ud-lt1_firmwareBrowse iodata / ud-lt1_firmwareDefault status: unknown | CVE List | Through 2.1.8 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-52564 iodata.jp
https://www.iodata.jp/support/information/2024/11_ud-lt1