Heap-based buffer overflow in Rockwell Automation products - CVE-2024-12372
Published: January 8, 2025
PowerMonitor 1000 PM1k 1408-BC3A-485
PowerMonitor 1000 PM1k 1408-BC3A-ENT
PowerMonitor 1000 PM1k 1408-TS3A-485
PowerMonitor 1000 PM1k 1408-TS3A-ENT
PowerMonitor 1000 PM1k 1408-EM3A-485
PowerMonitor 1000 PM1k 1408-EM3A-ENT
PowerMonitor 1000 PM1k 1408-TR1A-485
PowerMonitor 1000 PM1k 1408-TR2A-485
PowerMonitor 1000 PM1k 1408-EM1A-485
PowerMonitor 1000 PM1k 1408-EM2A-485
PowerMonitor 1000 PM1k 1408-TR1A-ENT
PowerMonitor 1000 PM1k 1408-TR2A-ENT
PowerMonitor 1000 PM1k 1408-EM1A-ENT
PowerMonitor 1000 PM1k 1408-EM2A-ENT
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.