ZeroHour

CVE-2024-50960

PoC ×2
CVSS 3.1
7.2 high
EPSS
2%p83
Published
()
Modified
Description

A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as root on the underlying operating system.

Vendors
extron
Products
smp 111 firmware, smp 351 firmware, smp 352 firmware, sme 211 firmware
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.