CVE-2024-22187 CRITICAL

CVE-2024-22187

Vendor Automationdirect
Product P3-550E
Weakness CWE-284
Published May 28, 2024
Last update February 13, 2025

CVSS base score

9.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

What the vulnerability does

01Description

A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to an arbitrary write. An attacker can send an unauthenticated packet to trigger this vulnerability.

Key dates

02Disclosure timeline

May 28, 2024 CVE published
February 13, 2025 Record updated