← back
CVE-2024-29838highCWE-20CWE-457

Unsanitised variable on DAL_ADD in Evolution Controller causes application level denial of service and crash

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 0.5%
exploitation probability
0.5%top 56% of all CVEs
observed exploitation
nono source reports it
The Web interface of Evolution Controller Versions 2.04.560.31.03.2024 and below does not proper sanitize user input, allowing for an unauthenticated attacker to crash the controller software
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H