CVE-2024-6596
Endress+Hauser: Multiple products are vulnerable to code injection
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Endress+Hauser · Echo Curve ViewerEndress+Hauser · FieldCare SFE500 Package USBEndress+Hauser · FieldCare SFE500 Package Web-PackageEndress+Hauser · Field Xpert SMT50Endress+Hauser · Field Xpert SMT70Endress+Hauser · Field Xpert SMT77Endress+Hauser · Field Xpert SMT79Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →